Microsoft Ads: Troubleshooting#

I see an AADSTS650052 error when I authorize Microsoft Ads#

The AADSTS650052: The app is trying to access a service (Microsoft Advertising API Service) that your organization lacks a service principal for error message appears when your organization’s Microsoft Entra ID tenant has never granted access to the Microsoft Advertising API.

Access to Microsoft Ads depends on two separate permission layers:

  • Microsoft Entra ID (Azure AD): your organization must consent to the Microsoft Advertising API at tenant level.

  • Microsoft Advertising: your user account must have a role that grants access to the accounts you want to collect data from.

Microsoft evaluates the Entra ID layer first. A user with the Super Admin role in Microsoft Advertising is still blocked if the tenant has not consented, because the two layers are independent of each other.

Important

This error cannot be resolved by changing Microsoft Advertising roles or permissions. It requires an administrator of your Microsoft Entra ID tenant, who is often not the same person as your Microsoft Advertising administrator.

To resolve this issue, ask an administrator with the Global Administrator, Application Administrator, Cloud Application Administrator, or Hybrid Identity Administrator role to do one of the following:

  1. Sign in to Microsoft Advertising directly with an administrator account, which registers the Microsoft Advertising API for your tenant.

  2. Grant admin consent for the Microsoft Advertising API in the Microsoft Entra admin center.

As a result, users in your organization can authorize Microsoft Ads. This is a one-time action for the whole tenant.

I see a “Need admin approval” screen when I authorize Microsoft Ads#

This screen appears for the same reason as the AADSTS650052 error above: the permission that Adverity requests must be consented to at Microsoft Entra ID tenant level, and your account cannot grant it on its own.

Follow the resolution steps described above.

The authorization is valid but fetches fail with an authorization error#

The status shown for an authorization records the result of the last time the credentials were checked. Adverity does not re-check them on a schedule, and a failed fetch does not change the status. An authorization can therefore show as valid while fetches fail.

The two checks also use different Microsoft services. An authorization that can list your accounts can still be refused when it requests a report.

To resolve this issue, re-authorize the authorization.

I fetch data successfully but my datastream is disabled afterwards#

Adverity disables a datastream automatically when Microsoft reports that the credentials are permanently invalid, which happens when the password of the authorizing user changes or when the refresh token expires after a long period without use. The authorization can still show as valid, because its status is not updated by a failed fetch.

To resolve this issue, re-authorize the authorization and enable the datastream again.

No accounts are available after I authorize Microsoft Ads#

Adverity retrieves the accounts that are linked to the Microsoft user account you authorized with. An account that is not linked to that user is not returned, regardless of the role that user holds in Microsoft Advertising.

Holding the Super Admin role does not by itself link your user to an account. This is also why you can see some of your accounts but not others: only the linked ones are returned.

To resolve this issue, ask a Microsoft Advertising administrator to add the authorizing user to each account you want to collect data from, then synchronize the metadata for the authorization. For more information, see Synchronizing metadata.

My data contains fewer rows than the Microsoft Advertising interface#

By default, Adverity excludes rows where every performance metric is zero. Microsoft Advertising includes these rows, so the two row counts differ.

The Include empty rows option controls this behavior, but it is only available for the Ad Performance, Campaign Performance, Ad Group Performance, and Asset Group Performance report types. For all other report types, rows with no performance data are always excluded.

Note

Adverity also removes duplicate rows from every report. If you select a set of columns that does not distinguish between rows, rows that Microsoft Advertising reports separately are combined into one.