← Back to desktop
Meta Ads

Setting Up Your First Meta Ad Account Correctly

NUVIX · 21 September 2026 · 10 min read
TLDR: Create the Business Portfolio in the business's own name, keep ownership there, and give your agency partner access rather than a login. Verify the domain, complete business verification when Meta requires it, set a spending limit before launch, and test the Pixel or dataset before launch, with the Conversions API deduplicated if you use it. If an account gets restricted, appeal through Meta's own review process. Do not open a second account to get around it; Meta treats that as evasion.

Start with the business, not the account

The single most common mistake in a first Meta setup is treating the ad account as the thing that matters. It isn't. The thing that matters is the Business Portfolio (what most people still call Business Manager), because that's the container that holds the ad account, the Page, the Pixel or dataset, and the people who can touch any of them. Meta's own overview explains that a Business Portfolio is where you manage business assets and control who has access to them, rather than a personal profile doing double duty as a company account.

Create the portfolio under the business's legal or trading name, using a work email the business controls, not a personal Gmail address and not an agency's inbox. Ownership of the portfolio, the Page and the ad account should sit with the business. If you ever change agency, you keep the account, the Page, the audiences and the years of ad history. Losing that because an agency built everything under its own portfolio is a genuinely common and entirely avoidable problem.

Partner access, not shared logins

Once the business portfolio exists, add your agency as a partner rather than handing over admin credentials. Meta's guidance on adding partners to a Business Manager sets out the mechanism directly: you share your Business Manager ID with the partner, and the partner requests access to specific assets, the ad account, the Page, a catalogue, with a defined role, rather than being handed the keys to everything.

Two-factor authentication should be switched on for the portfolio itself, and Meta lets an owner require it for admins or for everyone with access. Meta's help centre on turning on the two-factor authentication requirement is explicit that once it's enabled at the portfolio level, every person with access has to have 2FA on their own Facebook account before they can get in. Do this before you invite anyone else in, not after.

Inheriting an account someone else set up wrong? We'll audit the ownership, access and tracking before you spend another pound.

Book a 30 minute call

Verification: business, then domain

Two separate checks sit under the word "verification" and it's worth keeping them apart. Business verification confirms the legal entity behind the portfolio actually exists. Not every portfolio needs it straight away, and eligibility and accepted documents vary, so check the current instructions in the Security Centre and complete it when Meta prompts you or a feature you need requires it. Make sure the legal name and address on your documents match the details in the portfolio.

Domain verification is separate and confirms the business controls the website the ads point to, done through a DNS TXT record, an HTML meta tag or an uploaded file. Whichever checks apply, keep ownership records and admin access in the business's own name, not an individual's or an agency's, so there's no ambiguity about who controls the Portfolio, the Page or the domain later.

Payment method and spending limits, in the right order

Add a business payment method rather than a personal card wherever that's an option, so the paper trail matches the entity that owns the account. Before launching, set an account spending limit inside the ad account's billing settings. This is a cumulative limit: once total spend on the account reaches it, delivery stops until you raise it, which is useful insurance against a runaway campaign or a compromised login racking up spend while nobody's watching. It doesn't replace reviewing your actual billing, invoices and tax treatment separately, that's a finance and accounting question, not something the spending limit settles on its own. Set it, then review it monthly rather than leaving it at whatever default got picked on day one.

Pixel, dataset and the Conversions API

Meta's terminology has shifted: what used to be called simply "the Pixel" now sits inside Events Manager as a dataset, and the dataset ID is the same numeric ID the Pixel always had, so nothing already wired up breaks. Meta's setup guide for the Pixel walks through creating it from Events Manager under Connect Data, naming it, and installing the base code, either directly, through a tag manager, or through a partner integration.

Browser-only tracking has been unreliable since Apple's tracking-prevention changes, which is why the Conversions API exists: it can send the same events server-side, so a lost browser signal doesn't automatically mean a lost conversion. It isn't something every new account needs on day one, and it isn't a way to work around consent or iOS privacy controls: only send events you have a lawful basis and permission to send, and never send sensitive personal data as an event parameter. If you run both the browser Pixel and the Conversions API for the same event, send a shared event_id on both so Meta can deduplicate them, and check Events Manager for duplicate or missing events once it's live rather than assuming it's wired up correctly. We've covered the iOS side of that problem in more detail in our piece on Meta ads tracking after iOS 14. Meta's developer documentation for the Conversions API is the reference for the actual event payloads and matching parameters, and its troubleshooting guide is where to go when events aren't landing.

Before you launch anything, open the Test Events tab in Events Manager and fire a real event from the site, an add to cart, a form submit, whatever your key action is, and confirm it arrives with a healthy match rate before you trust the numbers it reports later. If you're building this alongside GA4 and Google Ads, our conversion tracking setup guide covers the equivalent groundwork on that side, and if consent banners are part of the picture, see our piece on consent mode.

Connect the Page and Instagram account properly

The ad account needs a Page to advertise from, and if you're running on Instagram too, connect that account through the same Business Portfolio rather than logging in on someone's phone. Assign the Page as a business asset under the portfolio, then give the agency partner access to it the same way you did the ad account.

Special ad categories: get this right before launch

If what you're advertising touches housing, employment, financial products and services (which includes credit), or is about social issues, elections or politics, Meta requires you to declare the relevant special ad category yourself before the campaign runs; don't rely on Meta's review to catch it for you. Housing, employment and financial products and services carry the strictest targeting limits, particularly for advertisers in, or reaching audiences in, the US, Canada or Europe: age options are generally fixed across the full adult range, gender targeting isn't available, geographic targeting can't go narrower than a wide radius, and lookalike or detailed-interest audiences built on those exclusions aren't available either, because those restrictions exist to stop unlawful discrimination in housing, credit and employment advertising. Exactly which restrictions apply can depend on the market you're targeting, so check the category against your actual audience rather than assuming the rules are the same everywhere. Meta's guidance on choosing a special ad category and its developer documentation on special ad categories cover the current detail.

The issues, elections or politics category works differently again. Since 6 October 2025, Meta has stopped allowing ads about social issues, elections or politics in the EU altogether, in response to the EU's incoming transparency rules for political advertising; this doesn't affect ordinary organic posts about politics, only paid ads. Outside the EU, where Meta still allows this category, running it means completing a separate authorisation process and adding a verified "Paid for by" disclaimer, covered in Meta's own guidance on getting authorised to run these ads. That process has its own timeline, so start it early if it applies to your market.

What to check the week before you spend

  1. Business Portfolio created and owned by the business, not the agency
  2. Agency and any freelancers added as partners with scoped access, not shared logins
  3. Two-factor authentication required for the portfolio
  4. Business verification completed when Meta requires it, with documents matching the portfolio's legal name and address
  5. Domain verified via DNS, meta tag or file upload
  6. Payment method added and an account spending limit set before launch
  7. Dataset created and base code installed; if you use the Conversions API, events deduplicated with a shared event_id
  8. Test event fired and confirmed in Events Manager before launch
  9. Special ad category declared if the campaign touches housing, employment, financial products and services, or social issues, elections and politics (social issue, electoral and political ads are not available in the EU since 6 October 2025)
  10. Page and Instagram account connected through the portfolio, not a personal login

What we would not do

We will not tell you to buy an aged or "pre-warmed" account, run several accounts to spread risk, or open a fresh account to get around a restriction on an old one. Meta's account integrity standard treats assets recreated or repurposed to evade a previous enforcement action as evasion in their own right, and it applies to accounts assessed as having common ownership with something already removed.

If an account gets disabled or restricted, the route back is Meta's own review process through Business Support Home: confirm your identity, secure the account, and request a review as an admin. Follow the deadlines and document requests shown there, and expect it to take time. There is no shortcut that is faster or safer than going through it properly.


Sources