# create_microsoft_ads_campaign

Build a campaign on a connected Microsoft Advertising (Bing Ads) account. ALWAYS created Paused — it spends NOTHING until you activate it with set_microsoft_ads_status(confirm:true). Microsoft’s object graph is campaign -> ad group -> responsive search ad -> keywords, so a campaign ON ITS OWN CANNOT SERVE AN IMPRESSION: pass adGroup{name, ad{headlines,descriptions,finalUrls}, keywords[]} and this builds the whole tree. Microsoft has NO atomic multi-object write (unlike Google), so the levels are created in sequence and the campaign is DELETED again if anything below it is rejected — you never inherit a half-built campaign. Microsoft requires 3–15 headlines (≤30 chars) and 2–4 descriptions (≤90 chars); expanded text ads can no longer be created at all. dailyBudget is in the ACCOUNT’S currency, not necessarily USD. LOCATION TARGETING: pass locations[] (country / region / city names, ISO country codes, or numeric Microsoft location ids). A Microsoft campaign has NO geo targeting unless it is set, and Microsoft does not require any — so if you pass none, the campaign IS CREATED and serves WORLDWIDE (Microsoft’s own default), and the returned note says so loudly. That is safe at this stage because the campaign is Paused and spends nothing; it is NOT safe to activate without telling the user, so relay the warning. Nothing is created when a location you DID name cannot be resolved (call microsoft_ads_geo_search to disambiguate, then pass the id). Pass worldwide:true to record that everywhere was deliberate and suppress the nudge. The locations are written and READ BACK inside the same rollback as the rest of the tree, so a campaign is either targeted as asked or does not exist. Everything is READ BACK from Microsoft before you are told it exists; print the returned note verbatim, and if it says the campaign cannot serve yet, say that rather than calling it a finished ad.

Agent View of the PolicyLayer registry record for `create_microsoft_ads_campaign`. HTML page: https://policylayer.com/tools/hermoso/create-microsoft-ads-campaign

## Facts

- Tool: `create_microsoft_ads_campaign`
- Server: Hermoso (`https://app.hermoso.ai/mcp`) — https://policylayer.com/tools/hermoso.md
- Homepage: git+https://github.com/hermoso-ai/hermoso.git
- Risk category: Write (Medium risk)
- Registry record: grade D, identity unverified
- Server auth posture: gated
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "create_microsoft_ads_campaign",
    "arguments": {}
  }
}
```

## Why create_microsoft_ads_campaign is rated Medium

An AI agent can call create_microsoft_ads_campaign faster than any human can review: one bad instruction and it creates or modifies resources in Hermoso by the hundred, each call as confident as the last.

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents use create_microsoft_ads_campaign to create or update resources in Hermoso, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Hermoso environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Hermoso:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "create_microsoft_ads_campaign": {
      "limits": [
        {
          "counter": "create_microsoft_ads_campaign_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Hermoso (895)

- `answer_google_business_question` — Destructive — https://policylayer.com/tools/hermoso/answer-google-business-question.md
- `apple_ads_change_history` — Destructive — https://policylayer.com/tools/hermoso/apple-ads-change-history.md
- `associate_linkedin_conversion_campaigns` — Destructive — https://policylayer.com/tools/hermoso/associate-linkedin-conversion-campaigns.md
- `cancel_openai_ads_audience_operation` — Destructive — https://policylayer.com/tools/hermoso/cancel-openai-ads-audience-operation.md
- `cancel_scheduled` — Destructive — https://policylayer.com/tools/hermoso/cancel-scheduled.md
- `cancel_stripe_subscription` — Destructive — https://policylayer.com/tools/hermoso/cancel-stripe-subscription.md
- `clear_sheet_range` — Destructive — https://policylayer.com/tools/hermoso/clear-sheet-range.md
- `create_analytics_custom_dimension` — Destructive — https://policylayer.com/tools/hermoso/create-analytics-custom-dimension.md
- `create_openai_ads_campaign` — Destructive — https://policylayer.com/tools/hermoso/create-openai-ads-campaign.md
- `delete_analytics_key_event` — Destructive — https://policylayer.com/tools/hermoso/delete-analytics-key-event.md
- `delete_apple_ads_object` — Destructive — https://policylayer.com/tools/hermoso/delete-apple-ads-object.md
- `delete_bluesky_post` — Destructive — https://policylayer.com/tools/hermoso/delete-bluesky-post.md
- `delete_brand` — Destructive — https://policylayer.com/tools/hermoso/delete-brand.md
- `delete_creator` — Destructive — https://policylayer.com/tools/hermoso/delete-creator.md
- `delete_dm_automation` — Destructive — https://policylayer.com/tools/hermoso/delete-dm-automation.md
- `delete_drive_file` — Destructive — https://policylayer.com/tools/hermoso/delete-drive-file.md
- `delete_google_ads_object` — Destructive — https://policylayer.com/tools/hermoso/delete-google-ads-object.md
- `delete_google_business_post` — Destructive — https://policylayer.com/tools/hermoso/delete-google-business-post.md
- `delete_instagram_dm_automation` — Destructive — https://policylayer.com/tools/hermoso/delete-instagram-dm-automation.md
- `delete_linkedin_ads_object` — Destructive — https://policylayer.com/tools/hermoso/delete-linkedin-ads-object.md
- `delete_linkedin_comment` — Destructive — https://policylayer.com/tools/hermoso/delete-linkedin-comment.md
- `delete_linkedin_lead_subscription` — Destructive — https://policylayer.com/tools/hermoso/delete-linkedin-lead-subscription.md
- `delete_merchant_data_source` — Destructive — https://policylayer.com/tools/hermoso/delete-merchant-data-source.md
- `delete_merchant_product` — Destructive — https://policylayer.com/tools/hermoso/delete-merchant-product.md
- `delete_messenger_marketing_campaign` — Destructive — https://policylayer.com/tools/hermoso/delete-messenger-marketing-campaign.md
- `delete_meta_audience` — Destructive — https://policylayer.com/tools/hermoso/delete-meta-audience.md
- `delete_meta_catalog` — Destructive — https://policylayer.com/tools/hermoso/delete-meta-catalog.md
- `delete_meta_object` — Destructive — https://policylayer.com/tools/hermoso/delete-meta-object.md
- `delete_microsoft_ads_object` — Destructive — https://policylayer.com/tools/hermoso/delete-microsoft-ads-object.md
- `delete_microsoft_merchant_product` — Destructive — https://policylayer.com/tools/hermoso/delete-microsoft-merchant-product.md
- …and 865 more: https://policylayer.com/tools/hermoso.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=hermoso · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/hermoso
