• Skip to primary navigation
  • Skip to main content
logo

ahrevs

  • Home
  • Services
    • Business Web Hosting
    • Business Email Hosting
    • Website Support & Maintenance
    • Forms, Email & Deliverability
    • Website Integrations
    • Website Migrations
    • Security & Reliability
    • Website Audits
  • About
  • Blog
  • Contact

Google Ads Is Requiring Passkeys: What Small Business Owners Need to Know

ahrevs · August 18, 2026 · Leave a Comment

If you run Google Ads for your business, there’s a security change you should know about—and this is one of those emails from Google that you probably shouldn’t ignore.

Google is beginning to require passkeys for certain sensitive actions inside Google Ads. Advertisers receiving the current notice are being told that beginning August 19, 2026, they may not be able to perform actions such as adding users or linking accounts without first setting up a passkey.

The good news: this isn’t nearly as complicated as it sounds.

The better news: it can actually make your Google account considerably harder to steal.

And if Google Ads is important to your business, I’d go a step further and consider using a physical security key such as a YubiKey.

Here’s what all of that means in normal English.

First: What Is a Passkey?

A passkey is basically a replacement for—or supplement to—the old combination of:

Username + password + security code

Instead of proving you’re you by typing something that another person could potentially steal, a passkey uses a device you already control.

That might be:

  • Your iPhone using Face ID
  • Your Android phone using your fingerprint or PIN
  • Your Windows computer using Windows Hello
  • A Mac using Touch ID
  • A physical security key such as a YubiKey

Google describes passkeys as a more secure alternative to passwords because they can’t simply be guessed, copied or handed over to somebody through a phishing attack.

Here’s a simple example.

You’re a plumber and receive an email that looks exactly like it came from Google:

“Your Google Ads account has been suspended. Click here immediately.”

You click the link.

The website looks like Google.

It asks for your email.

You enter it.

It asks for your password.

You enter that too.

With an old-fashioned login system, you may have just handed an attacker exactly what they needed.

A passkey works differently.

There isn’t a reusable password sitting there waiting to be stolen and entered on another computer. The authentication depends on a cryptographic credential associated with your device.

That’s a big part of why passkeys are considered phishing-resistant.

Why Should a Small Business Owner Care?

Because your Google Ads account isn’t just another website login.

For many businesses, it controls real money and a major source of incoming customers.

Think about a local electrician spending $5,000 per month on Google Ads.

Or a dentist spending $10,000.

Or a law firm spending considerably more.

If someone gets control of that Google account, this isn’t like having your Netflix password stolen.

An attacker could potentially interfere with advertising, users, account connections or billing-related settings.

Google specifically says passkeys may be required when completing sensitive actions including adding users, changing billing information and updating account links.

That’s exactly the type of stuff you don’t want someone changing because they successfully tricked an employee into typing a password into a fake Google page.

Does This Mean Your Password Stops Working?

No.

This part is important.

Google’s current documentation says you can still use your regular password and existing two-step verification methods for normal account login.

The passkey requirement comes into play when Google asks you to confirm your identity before performing certain sensitive Google Ads actions.

So this isn’t necessarily:

“Passwords disappear on August 19.”

It’s more like:

“Before we let you make an important change to this advertising account, prove that you’re really you using something much harder for a scammer to steal.”

That’s a reasonable security improvement.

So What’s a YubiKey?

This is where I think things get particularly useful for business owners.

A YubiKey is a small physical security key made by Yubico.

It looks somewhat like a tiny USB drive.

Depending on the model and device you’re using, you plug it into your computer or use NFC, and physically interact with the key when you’re authenticating.

YubiKeys support FIDO2, the technology Google supports for hardware-based passkeys. Google specifically lists FIDO2-compatible hardware security keys as supported passkey devices.

Think of it as having an actual key to important online accounts.

Someone in another country might somehow figure out your password.

They could trick an employee.

They could create a beautiful fake Google login screen.

But it’s considerably harder for them to remotely steal the little physical key sitting on your keychain.

Do You Need a YubiKey?

No.

I want to make that clear.

Google is requiring a passkey in certain situations. Google is not requiring you to buy a YubiKey.

You can create a passkey using a compatible phone or computer.

For many people, that’s perfectly reasonable.

But for a small-business owner controlling important systems—Google Ads, company email, financial accounts, website administration and other critical services—I like the idea of having a separate physical security device.

My preference would be:

Use a FIDO2-compatible YubiKey as one of your important authentication methods and have a second key registered as a backup.

Yubico itself recommends having more than one YubiKey: one primary key and another stored safely as a spare. Google also recommends having another security key or recovery method available in case a security key is lost.

It’s the same reason you don’t want your only house key to be the one in your pocket.

“Wait. Two YubiKeys?”

For important business accounts, yes, that’s what I would do.

Key #1 can stay with you.

Key #2 can stay somewhere secure.

Don’t put both on the same keyring.

That rather defeats the point.

If your backpack disappears at an airport with your laptop, phone and both YubiKeys inside it, congratulations: your beautifully redundant security system has just become one very secure lost backpack.

Keep the backup somewhere else.

What Small Businesses Should Do Now

If you’ve received Google’s passkey notice, I would not wait until the day you actually need to make an account change.

Google’s current documentation says new passkeys generally take about one to two days to pair with Google Ads, while its troubleshooting information also warns that a new passkey may be subject to a security delay of up to seven days.

In other words:

Set it up before you need it.

Here’s what I’d do.

1. Go Directly to Your Google Account

Don’t use a link from some random email telling you your account is about to explode.

Open Google yourself and go into your Google Account security settings.

Look for:

Security → Passkeys and security keys

Google’s official setup process lets you create a passkey from there.

2. Create a Passkey

You can use your phone, computer or compatible hardware security key.

If you’re using a YubiKey, choose the option to use a security key when Google asks where you want to create the passkey.

3. Don’t Create Business Passkeys on Shared Computers

This one should be obvious, but small businesses sometimes have one computer at the front desk that everybody uses.

Don’t make that machine the crown jewel of your company’s authentication system.

Google specifically advises against creating passkeys on shared devices.

Use a device you personally control.

4. Stop Sharing One Google Login With Everybody

This is another important change.

If three employees, your marketing company and your cousin Steve all know the password to companygoogleaccount@gmail.com, you already have a security problem.

Passkeys are designed around individual identities.

Google says shared agency logins are discouraged and recommends giving individual users their own access instead.

That’s how a business account should be structured anyway.

Your employee gets access.

Your marketing company gets access.

Your PPC person gets access.

Nobody needs your master password.

And when somebody leaves, you remove their access.

5. Check Google Ads

Inside Google Ads, administrators can go to:

Admin → Access and security

Google now provides a Passkey status column showing whether users have passkeys enabled.

If several people manage your account, this is worth reviewing.

6. Have a Backup

Whether your passkey lives on your phone, computer or YubiKey, think about what happens when that device disappears.

Phones break.

Laptops die.

Keys get lost.

Employees leave.

Set up your recovery options before you’re standing in a hotel lobby with a dead phone trying to figure out why nobody can access the company’s advertising account.

One More Warning: Passkey Phishing Is Going to Be a Thing

There’s a wonderfully predictable cycle in cybersecurity.

Company announces new security feature.

Users don’t understand it.

Scammers immediately send emails saying:

URGENT: YOUR NEW SECURITY FEATURE MUST BE ACTIVATED IMMEDIATELY. CLICK HERE.

So don’t be surprised if fake “Google Passkey Required” emails start showing up.

Whenever possible, avoid using an unexpected email link to configure something as important as your Google Account security.

Open Google directly.

Go into your account.

Make the change there.

This Is Bigger Than Google Ads

Google Ads happens to be forcing the issue for some advertisers right now, but passkeys aren’t just a Google Ads thing.

Google supports passkeys across Google Accounts, and the underlying technology is an industry standard supported by modern devices and browsers.

You’re going to see the word passkey more and more.

And that’s probably a good thing.

Passwords have had a pretty impressive run considering how terrible humans are at creating them.

For decades we’ve been told:

Don’t reuse passwords.

Make them complicated.

Don’t write them down.

Change them.

Don’t click phishing links.

Use two-factor authentication.

Don’t give anyone your verification code.

And somehow the password is still:

Fluffy2026!

Passkeys remove a lot of that human weakness from the equation.

My Recommendation for Small Businesses

If Google Ads matters to your business and you’ve received the passkey notification, set up your passkey now rather than waiting until you need to make an important account change.

Using your phone or computer is fine.

For owners, administrators and anyone with access to especially important business accounts, I would seriously consider using a FIDO2-compatible YubiKey as well.

And buy/register a second one as your backup.

Then start looking beyond Google Ads.

Your business email account is arguably even more important. If someone owns your email, they can often use it to reset passwords for everything else.

Your Google account, Microsoft account, domain registrar, website hosting, password manager and other critical business systems deserve more protection than a password somebody created four years ago and has since reused on 17 websites.

Security doesn’t have to mean hiring a cybersecurity team or understanding cryptography.

Sometimes it can be as simple as:

Here’s my password.

Becoming:

Here’s my physical key. Prove I actually have it.

For a small business, that’s a meaningful upgrade.

Wordpress Security

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 · Handcrafted with in Chicago · Powered by ahrevs