How to Manage Admins on Meta Business Portfolio

Article author
Learning Center Mekari
  • Updated

To maintain security and ensure smooth business asset management, it is recommended to add more than one admin to your Meta Business Portfolio. This way, you can access and manage business assets if the primary admin encounters issues. In this guide, you will learn how to manage Admins on Meta Business Portfolio, including backup Admins, and how organizations can secure admin accounts with Two-Factor Authentication (2FA).

Important
Before adding an admin to your Meta Business Portfolio, make sure the Facebook account to be used is at least 30 days old and is not currently under any restrictions (restriction) by Meta.

Reason Explanation
Account Recovery
(Account Recovery)
If the primary admin loses access to the account, for example due to hacking, forgotten credentials, or account deactivation, a backup admin can still access and recover the Meta Business Portfolio.
Business Continuity
(Business Continuity)
Business activities can continue because backup admins can manage business assets such as ad accounts, Facebook Pages, and WhatsApp Business Accounts (WABA) until issues with the primary admin are resolved.
Security and Access Control
(Security & Access Control)
Adding more than one admin helps avoid dependence on a single user (single point of failure), making access management more secure.
Delegation and Collaboration
(Delegation & Collaboration)
In organizations with many team members, multiple admins can share tasks and responsibilities, making business asset management more efficient.
Emergency Response
(Emergency Response)
In urgent situations, such as account restrictions, ad rejections, or payment issues, backup admins can promptly take necessary actions.

Meta's Best Practice
(Meta's Best Practice)

Meta recommends that each Meta Business Portfolio has at least two admin accounts to enhance security and ensure business management runs smoothly.

A. How to Add an Admin

  1. Open your Meta Business Portfolio page, then go to the Users section, specifically under People.
  2. On the left panel, click the “People” menu, then click “Invite people” in the upper right corner.
    3.png
  3. Enter the email address of the user linked to their Facebook account, then click “Enter”. Next, click “Next”.
  4. Select the role (Business Role) to assign. If you want to grant full control to the user, toggle on “Manage”. Then click “Next”.
  5. As an Admin, you can provide limited access and adjust permissions later (optional). Assign business assets (Assign Assets) that the user can access, such as Facebook Pages, ad accounts, apps, or WhatsApp Business Accounts (WABA). Click “Invite” to send the invitation. The user will receive the invitation via email and must accept it first to join the Meta Business Portfolio.

  6. Once the user has accepted the invitation and logged in, their name will appear on the People page.

B. Securing Admin Accounts with Two-Factor Authentication (2FA)

On Facebook, Two-Factor Authentication (2FA) is an additional security layer that helps ensure only authorized users can access business assets.

Important
To enhance account security, it is highly recommended to enable Two-Factor Authentication (2FA). You can learn how to enable 2FA through the Facebook security settings page.

Meta provides several 2FA methods you can use, as follows:

1. Authentication App (Highly Recommended)

Use an authentication app such as Google Authenticator, Duo, or Authy. After setup, the app generates a verification code that refreshes every 30 seconds. This method is the most recommended because the code is available in real-time and does not rely on phone numbers for OTP delivery via SMS or WhatsApp.

2. Text Message (SMS)

Verification codes are sent via SMS to the registered phone number. This method is easier to set up but has lower security compared to using an Authentication App.

3. Security Key (Advanced)

This method uses a physical device, such as a USB or NFC key (e.g., YubiKey), which must be connected during the login process. Although it offers very high security and is suitable for high-risk accounts, this method is less recommended due to the risk of losing or damaging the physical device.