create_microsoft_ads_campaign
Build a campaign on a connected Microsoft Advertising (Bing Ads) account. ALWAYS created Paused — it spends NOTHING until you activate it with set_microsoft_ads_status(confirm:true). Microsoft’s object graph is campaign -> ad group -> responsive search ad -> keywords, so a campaign ON ITS OWN CAN...
This record as markdown: /tools/hermoso/create-microsoft-ads-campaign.md
What create_microsoft_ads_campaign does on Hermoso
AI agents use create_microsoft_ads_campaign to create or update resources in Hermoso, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hermoso environment.
Why create_microsoft_ads_campaign is rated Medium
An AI agent can call create_microsoft_ads_campaign faster than any human can review: one bad instruction and it creates or modifies resources in Hermoso by the hundred, each call as confident as the last.
Risk signalsBulk/mass operation — affects multiple targets
Attacks that exploit this kind of access
The rule that runs create_microsoft_ads_campaign safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Hermoso, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For create_microsoft_ads_campaign, this is the rule to start with:
create_microsoft_ads_campaign stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Hermoso, apply this rule, and every create_microsoft_ads_campaign call is checked against it from then on.
Questions about create_microsoft_ads_campaign
Build a campaign on a connected Microsoft Advertising (Bing Ads) account. ALWAYS created Paused — it spends NOTHING until you activate it with set_microsoft_ads_status(confirm:true). Microsoft’s object graph is campaign -> ad group -> responsive search ad -> keywords, so a campaign ON ITS OWN CANNOT SERVE AN IMPRESSION: pass adGroup{name, ad{headlines,descriptions,finalUrls}, keywords[]} and this builds the whole tree. Microsoft has NO atomic multi-object write (unlike Google), so the levels are created in sequence and the campaign is DELETED again if anything below it is rejected — you never inherit a half-built campaign. Microsoft requires 3–15 headlines (≤30 chars) and 2–4 descriptions (≤90 chars); expanded text ads can no longer be created at all. dailyBudget is in the ACCOUNT’S currency, not necessarily USD. LOCATION TARGETING: pass locations[] (country / region / city names, ISO country codes, or numeric Microsoft location ids). A Microsoft campaign has NO geo targeting unless it is set, and Microsoft does not require any — so if you pass none, the campaign IS CREATED and serves WORLDWIDE (Microsoft’s own default), and the returned note says so loudly. That is safe at this stage because the campaign is Paused and spends nothing; it is NOT safe to activate without telling the user, so relay the warning. Nothing is created when a location you DID name cannot be resolved (call microsoft_ads_geo_search to disambiguate, then pass the id). Pass worldwide:true to record that everywhere was deliberate and suppress the nudge. The locations are written and READ BACK inside the same rollback as the rest of the tree, so a campaign is either targeted as asked or does not exist. Everything is READ BACK from Microsoft before you are told it exists; print the returned note verbatim, and if it says the campaign cannot serve yet, say that rather than calling it a finished ad. It is categorised as a Write tool in the Hermoso MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Hermoso MCP server in PolicyLayer and add a rule for create_microsoft_ads_campaign: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Hermoso. Nothing to install.
create_microsoft_ads_campaign is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the create_microsoft_ads_campaign rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for create_microsoft_ads_campaign. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
create_microsoft_ads_campaign is provided by the Hermoso MCP server (https://app.hermoso.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Hermoso, and thousands of servers like it.
This server
Across the catalogue