A clipboard with a ticked checklist and a padlock on its clip in blue halftone, beside the headline Protect Your Business Accounts Start Here.

Protect Business Social Media Accounts: A Checklist

A checklist for Malaysian businesses: own your Meta portfolio and LinkedIn Page, keep two trusted admins, require 2FA, audit access and offboard staff.

11 min read
Short answer

Put every Page, Instagram account and ad account inside a Meta business portfolio your company owns. Keep two trusted people with full control, require two-factor authentication for everyone, and give others only the access they need. Audit access every quarter, remove leavers on their last day, and never share passwords or codes with anyone.

Summary
  • Your business should own its Facebook Pages, Instagram accounts and ad accounts inside its own Meta business portfolio, not inside a staff member's or an agency's.
  • Keep at least two trusted people with full control, require two-factor authentication for everyone in the portfolio, and store recovery codes where both owners can reach them.
  • Give everyone else only the access their job needs, add agencies as partners rather than admins, and use temporary access for short projects.
  • Every quarter, export the people list, remove anyone inactive or without two-factor, and remove staff and agencies on the day they leave.
  • Meta staff never ask for passwords or money over chat or email, so treat any message asking for your login, codes or a payment as a scam.
  • If something still goes wrong, recovery happens only through the platform's official processes, the platform makes the final decision, and some accounts do not come back.
Table of contents14 sections
  1. 01How Do You Protect Business Social Media Accounts?
  2. 02The Business Account Security Checklist
  3. 03Make Sure the Business Owns the Accounts
  4. 04Keep Two Trusted Admins With Full Control
  5. 05Require Two-Factor Authentication for Everyone
  6. 06Give Staff and Agencies Only the Access They Need
  7. 07Run a Quarterly Access Audit
  8. 08Offboard Staff and Agencies on Their Last Day
  9. 09Protect Your LinkedIn Company Page Too
  10. 10How to Recognise Fake Meta Support and Recovery Scammers
  11. 11Mistakes That Leave Business Accounts Exposed
  12. 12If Something Still Goes Wrong
  13. 13When a Case Review Makes Sense
  14. 14Frequently Asked Questions

Your shop's Facebook Page, Instagram account and LinkedIn Page were probably set up by whoever was free that week. Years later, one former staff member still has admin rights, the agency holds the ad account, and nobody is sure where the recovery codes went.

The short answer: make the business the owner of every account, keep two trusted people at the top, require two-factor authentication for everyone, and remove access the day it is no longer needed. Meta's own security advice for business portfolios is built around the same ideas.

This checklist covers Meta business portfolios (Facebook Pages, Instagram and ad accounts) and LinkedIn Pages, for small teams in Malaysia that do not have an IT department.

Last checked: 5 October 2026.

#How Do You Protect Business Social Media Accounts?

Control who owns the accounts and who can get in. Put every Page, Instagram account and ad account inside a Meta business portfolio that your company controls, with two trusted people holding full control. Turn on the portfolio's two-factor requirement for everyone, give staff and agencies only the access they need, and review the people list every quarter. On LinkedIn, keep two super admins, have every admin turn on two-factor, and give everyone else a narrower role. Personal password hygiene still matters, but for a business much of the risk sits in access that nobody is watching.

#The Business Account Security Checklist

Tick each row once, then repeat the review rows on schedule. Menu labels are as Meta and LinkedIn showed them on 5 October 2026 and can vary by app version and region.

Built from Meta Business Help Center and LinkedIn Help pages read on 5 October 2026.
ControlWhat good looks likeWhere to set itHow often
OwnershipEvery Page, Instagram and ad account sits in your own business portfolioMeta Business Suite, "Settings"Once, then on every new asset
Top-level adminsTwo or three named, active people with full control"Settings", then "People"Each quarter
Two-factor requirementSet to "Everyone""Settings", "Business portfolio info", "Business options"Once, then check it
Recovery codesEach admin has saved codes and a backed-up authenticatorEach person's own security settingsWhen a phone changes
Least accessStaff get partial access to their own tasks"Settings", then "People"Each quarter
AgenciesAdded as partners, limited to their tasks"Settings", then "Partners"Start and end of each contract
OffboardingLeavers removed on their last day"People" or "Partners", then "Remove"Every departure
Activity reviewBusiness history checked for unexpected changes"Settings", download business historyEach quarter, and after any alert
LinkedIn Page rolesTwo super admins; narrower roles for othersPage super admin viewEach quarter

#Make Sure the Business Owns the Accounts

A Meta business portfolio (formerly Business Manager) holds your Facebook Pages, Instagram accounts and ad accounts and decides who works on them. Meta's page on portfolio and asset permissions explains that people with full control can claim or remove assets and people, manage partner access, and even delete the portfolio. Whoever holds that role holds the business.

  • Create the portfolio under a company owner, not a freelancer, and claim each Page, Instagram account and ad account into it.
  • Use work email addresses where you can. Meta's security best practices suggest removing people whose email addresses are not related to your business.
  • Write down which portfolio owns which asset, its ID and who has full control, and keep the note offline.

If an agency or a former employee created the Page inside their own portfolio, the asset belongs to them in Meta's eyes, and only the owning organisation can share it onward. Our guides on what to do when an agency has locked you out of your Facebook Page and when a former employee still holds the company accounts cover that situation.

#Keep Two Trusted Admins With Full Control

One admin is a single point of failure. If that person's personal Facebook account is hacked, disabled or simply abandoned, the business can lose its top level of access with it.

Meta recommends, but does not require, two active people with full control. With second admin approval, sensitive actions such as sharing a credit line or changing another full-control person's access need a second person to approve. Meta also says to keep full control to those who need it, ideally 10 or fewer. For a small business, pick two or three people whose departure you would plan for, such as the owner and a long-serving manager, not a temporary hire or freelancer.

#Require Two-Factor Authentication for Everyone

Two-factor authentication asks for a code or a passkey on top of the password when someone logs in from an unrecognised device. Meta's page on requiring two-factor for a business portfolio says only people with full control can switch the requirement on, under "Settings", "Business portfolio info", then "Business options".

  1. Open the dropdown next to "Two-factor authentication".
  2. Choose "Everyone" so every person with any access needs it, rather than "Admins only".
  3. Confirm. Meta says the requirement takes effect immediately, and people without two-factor are prompted to set it up next time they try to enter the portfolio.
  4. Warn staff first. Anyone who browses in private mode, or clears history on closing, may be asked for a code every time because Meta cannot remember the device.

Meta automatically requires two-factor for some portfolios older than 90 days. For the method, it suggests a backed-up authenticator app plus saved recovery codes, and calls passkeys (fingerprint, face scan or screen lock) more secure than passwords and one-time codes. Its passkey page notes they are currently not supported in the Business Suite or Ads Manager mobile apps, so keep a second method. Store recovery codes offline, such as printed in the office safe or in a business password manager both owners can open, never in a chat group.

#Give Staff and Agencies Only the Access They Need

Meta has two levels: full control, and partial access limited to the assets or tasks someone is assigned, such as creating content, managing ads or answering messages. Meta's own advice is that giving people only the permissions they need keeps portfolios more secure. In practice:

  • A staff member who answers customer messages needs partial access to the Page, not the portfolio.
  • Someone who handles invoices may need finance access, which Meta lists as a separate option, without full control.
  • For a short campaign or a part-time helper, use temporary access. Meta says it gives basic access for between 3 and 75 days and removes the person automatically when it ends.
  • Add an agency as a partner, not as people with full control of your portfolio. Meta's page on giving a partner access says a partner, even with full control of an asset, cannot share it with another business. Partner access ends cleanly with the contract.

#Run a Quarterly Access Audit

Meta's best practices page says attackers target inactive accounts, and recommends removing people who have not logged in for 90 days, people without passkeys or two-factor, and people whose devices may carry malware. A review every quarter lines up with that 90-day mark.

  1. In Meta Business Suite "Settings", open "People" and export the permissions file. Meta says it shows when each person was last active and whether two-factor is on, but not pending invitations.
  2. Remove anyone inactive for 90 days, anyone without two-factor, and anyone you do not recognise.
  3. Check the "Partners" list. Remove agencies you no longer work with.
  4. Download the business history. Look for role changes, new invitations, changed two-factor settings and partner access you did not approve.
  5. On LinkedIn, open the Page super admin view and review every admin. LinkedIn recommends reviewing admin permissions periodically.
  6. Record the date and who did the review, so the next one is easy.

#Offboard Staff and Agencies on Their Last Day

Offboarding is easy to forget in a small team. A friendly ex-employee with old admin rights is still a risk, because their personal account can be hacked long after they leave.

  • Remove the person from the portfolio. Meta's page on removing people says this revokes their access to the portfolio and every asset, such as a Page, Instagram account or ad account, they could reach.
  • If a second admin must approve the removal, approve it under "Requests" in "Settings" the same day.
  • Remove a finished agency as a partner, which Meta treats as a separate step from removing a person.
  • Remove them as a LinkedIn Page admin and change any shared tool password they knew.
  • Check that no recovery email or phone number on a business asset still points to them.
  • If they held full control, confirm the remaining two admins can still log in before you finish.

#Protect Your LinkedIn Company Page Too

LinkedIn's page on admin roles lists the super admin, who can add and remove any admin, edit Page information and deactivate the Page; the content admin, who manages posts and events; and the analyst, who sees only analytics. Its guide to protecting your Page suggests assigning each admin the role that matches the access they need, such as analyst rather than super admin for someone who only exports analytics.

  • Keep two super admins, for the same reason as on Meta.
  • Ask every admin to turn on two-factor on their own LinkedIn account. LinkedIn says this protects their profile and every Page they administer, and offers an authenticator app, a phone number or a sign-in security prompt.
  • Add your company email domain so that only people with a work address can post jobs as your Page. LinkedIn says that without a domain, any member can post a job under your Page.
  • Post regularly. LinkedIn says inactive Pages can look unofficial.
  • Check whether Page verification is offered under "Verification controls" in the super admin settings. LinkedIn says it is not yet available to every Page and a request does not promise a badge.

If you have already lost admin access to your Company Page rather than trying to prevent it, see our guide on LinkedIn company page admin access lost.

#How to Recognise Fake Meta Support and Recovery Scammers

Business accounts attract scammers because a Page or ad account can be worth money. Meta's page on phishing warns that attackers have sent Business Manager partner requests containing phishing links, and that these notifications come from a real Meta domain, facebookmail.com. If you do not know the business in a partner request, do not click its links.

  • Meta says its representatives never request money or ask for passwords, payment details or other sensitive information over chat or email.
  • Real Meta email comes only from fb.com, facebook.com, facebookmail.com, instagram.com, meta.com or metamail.com and their subdomains, Meta says. A real domain can still carry a malicious partner request.
  • Threats that your Page will be deleted unless you act now, in English, Bahasa Malaysia or Chinese, are pressure tactics.
  • Anyone offering to recover, verify or protect your accounts who asks for your password, a login code or your backup codes is not helping you.
  • Never buy aged accounts or pages, and never use unofficial tools that promise to boost or restore access. They break platform rules and often end in a takeover.

Our article on the fake Meta support scam shows the common scripts in more detail.

#Mistakes That Leave Business Accounts Exposed

  • Several staff sharing one personal Facebook login.
  • Only one person with full control, who then leaves or loses their account.
  • Leaving two-factor on "Admins only", so staff with partial access have no second step.
  • Recovery codes kept in an inbox or chat an attacker would also reach.
  • Letting the agency create the Page or ad account inside its own portfolio.
  • Never opening the business history, so a new partner goes unnoticed for months.

#If Something Still Goes Wrong

Even a well-run setup can be hit. If an admin is removed or a Page is taken, report it through Meta's own help channels from an account that still has access, and see our guide to a hacked Facebook Business Manager for the first steps. Recovery is best effort. It runs only through the platform's official processes, the platform makes the final decision, and some accounts do not come back. The checklist above is what gives you the second admin, the codes and the records that make an official request possible.

#When a Case Review Makes Sense

Most businesses can work through this checklist on their own. A second opinion helps when you are not sure who really owns your Pages, when an agency or former staff member holds the portfolio, or when a takeover has already happened. SocialSafe by AwareXone, our recovery and account security service, looks at your setup or your case first and tells you plainly what an official route can and cannot do. You can read how our account security service works, and our Trust Center sets out what we never ask for, starting with your passwords and codes.

#Frequently Asked Questions

How many admins should a business Facebook Page have?
Meta recommends two active people with full control of the business portfolio and suggests keeping full control to 10 or fewer. Most small businesses do well with two or three trusted people at the top and partial access for everyone else.
Can I make two-factor authentication mandatory for my staff on Meta?
Yes. A person with full control can set the portfolio's two-factor requirement to "Everyone" in Meta Business Suite settings. Anyone without two-factor is then asked to set it up before they can enter the portfolio.
Should our agency be an admin or a partner?
A partner. Meta lets you give a partner business access to specific assets, and a partner cannot share your asset with another business. Removing the partner ends their access without touching ownership.
What happens when I remove a former employee from the business portfolio?
Meta says removing a person revokes their access to the portfolio and every business asset they could reach. Check afterwards that their email or phone is not set as a recovery contact anywhere.
Does LinkedIn Page verification stop impersonation?
It helps people find your official Page, but LinkedIn says verification is not available to every Page and does not confirm everything posted on it. You can still report duplicate or fake Pages to LinkedIn.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.