Microsoft Ads: Organization Hasn't Enabled the Advertising API
Problem
When you try to connect Microsoft Ads, the sign-in fails and you see:
Microsoft declined the sign-in because your organisation's Microsoft Entra (Azure AD) tenant has not enabled the Microsoft Advertising API for work accounts. Ask your IT admin to add the Microsoft Advertising API Service to your tenant, or sign in with the Microsoft account you use at ads.microsoft.com, then try connecting again.
This happens with a work or school Microsoft account (one tied to your company's Microsoft 365 / Azure subscription), not a personal Microsoft account.
Why This Happens
Every organization that uses Microsoft 365 or Azure has a Microsoft Entra tenant — the directory that holds your company's users, groups, and which outside applications are allowed to sign them in. Two Minute Reports uses Microsoft's own Advertising API to connect, and before any work account in your tenant can use it, an admin has to explicitly register that API with the tenant.
Most companies never need to do this until the first person tries to connect an advertising tool like Two Minute Reports — so this step is very often simply missing, not broken. It's a one-time setup per organization; once an admin does it, everyone in that organization can connect normally.
Solutions
Solution 1: Ask your IT admin to enable the Microsoft Advertising API
Send your IT admin this request. They need Global Administrator or Application Administrator rights in your Microsoft Entra tenant to complete it — this can't be done from a regular user account.
Using the Azure CLI (fastest, if your admin already has it installed and is signed in with az login):
az ad sp create --id d42ffc93-c136-491d-b4fd-6f18168c68fd
Using Microsoft Graph (for admins who prefer the API directly):
POST https://graph.microsoft.com/v1.0/servicePrincipals
{
"appId": "d42ffc93-c136-491d-b4fd-6f18168c68fd"
}
Both commands register the same thing: Microsoft's own "Microsoft Advertising API Service" application, so it's the same well-known ID every organization uses — it's not specific to Two Minute Reports or to your account.
Once your admin has run either command, try connecting Microsoft Ads again — no further waiting is required.
Solution 2: Sign in with an individual Microsoft account instead
If you have a personal Microsoft account you already use directly at ads.microsoft.com — separate from your work account — you can sign in with that instead when connecting. Personal accounts aren't tied to your organization's tenant, so this restriction doesn't apply to them.
This only works if the ad accounts you need are actually accessible from that personal account.
Still Seeing the Error?
If your admin has already run one of the commands above and you still see this error:
- Confirm which Microsoft account you tried signing in with (work or personal)
- Ask your admin to confirm the command completed without an error
- Contact [email protected] with that information
Our support team can help confirm whether the tenant is correctly configured.
Google Says "Service unavailable" When You Open the Add-On
Fix Google's "Service unavailable — you tried to access a service that isn't available for your account" screen when you open the Two Minute Reports add-on in Google Sheets.
Overview
Tips and best practices for getting the most out of Two Minute Reports with Google Sheets and Google Data Studio.