Microsoft Ads Click Fraud: What Microsoft Filters, What It Misses, and How to Protect Your Budget

Dan Slay
Dan Slay
Founder
| 14 min read Click Fraud 21 September 2026

Table of contents

Microsoft Ads click fraud is the same problem as Google Ads click fraud with a different set of tools pointed at it. Someone or something clicks your Microsoft Advertising ads without any intention of becoming a customer, and you pay for it. What changes between the two platforms is not the fraud itself but what you can see, what you can block, and how much the platform tells you about the clicks it quietly throws away.

Most advice written for advertisers assumes Google Ads. If you run Microsoft Advertising, formerly Bing Ads, you have probably noticed that the buttons are in different places and some of them do not exist at all. This guide covers what Microsoft actually does about invalid clicks, where the reporting is genuinely useful, where it falls short, and what you can do yourself before reaching for a paid tool.

How Microsoft Advertising grades every single click

Microsoft Advertising sorts every click on your ads into one of three buckets: standard-quality, low-quality, or invalid. This is Microsoft’s own framework, set out in its guidance on monitoring clicks, and it is the single most useful thing to understand about traffic quality on the platform.

Standard-quality clicks are the ones Microsoft believes came from potential customers. Low-quality and invalid clicks, in Microsoft’s words, typically do not result in conversions or value to your business, and often come from spiders, robots, questionable sources or test servers.

The billing rule follows from that grading. You only get billed for standard-quality clicks. If Microsoft charges you for a click and later decides it was low-quality or invalid, your bill is adjusted. If Microsoft suspects invalid clicks generated by search engine robots, automated clicking tools or other fraudulent means, it credits the account automatically.

That sounds tidy, and up to a point it is. Google Ads works on a broadly similar principle, which we covered in detail in our guide to Google’s invalid click protection and why it is not enough. The catch on both platforms is the same: the filtering protects the advertising ecosystem as a whole rather than your particular campaign, and it is tuned to avoid false positives. Anything that looks passably human tends to get through.

The reporting quirk that confuses almost everyone

Here is the detail that causes more confusion than anything else on the platform. Microsoft states plainly that when it credits you for clicks it later judged low-quality or invalid, those clicks will remain listed in your reports as standard-quality clicks.

So the number in your Clicks column is not a clean count of clicks you paid for. Some of them were refunded behind the scenes without the report changing. If you have ever tried to reconcile your Microsoft Advertising click count against your website analytics and given up, this is part of the reason why. It is also why click counts in Microsoft Advertising and sessions in Google Analytics will never match, a mismatch we unpack more generally in our guide to bot traffic in Google Analytics.

The practical consequence is that you cannot audit Microsoft Ads click fraud by staring at your click totals. You have to look at the metrics Microsoft breaks out separately, and then at what those clicks actually did once they landed on your site.

Where to find low-quality click data in Microsoft Advertising

Microsoft Advertising reports low-quality clicks as a metric you have to switch on yourself. In the Report Builder, you can add Low-quality clicks and Low-quality click rate (%) to a performance report using the column modifier. Neither appears by default, which is why most advertisers have never seen their own numbers.

Run that report at campaign and ad group level over at least ninety days. You are not looking for a magic threshold, because no honest benchmark exists for what a normal low-quality click rate should be. You are looking for outliers: one campaign well above the others, or a rate that climbs sharply in a particular week. A single high-CPC campaign carrying most of the low-quality clicks is the pattern worth investigating.

Two other reports earn their keep here. The Website URL (Publisher) report shows where your ads actually served across the Microsoft Advertising Network, which matters enormously on a platform with syndicated search partners. And conversion tracking through Universal Event Tracking gives you the conversion rate you need to spot the classic warning sign: clicks holding steady or rising while enquiries fall. That symptom is not proof of fraud on its own, and we walk through the other seven explanations in our post on why Google Ads campaigns get clicks but no enquiries, most of which apply equally to Microsoft Advertising.

Microsoft is also refreshingly honest that click spikes often have boring causes. Its own documentation lists seasonal demand, a promotion, a news event, a change to your ad copy or website, and new inbound links as reasons your click volume might jump. Rule those out before you assume an attack.

Why Microsoft Ads click fraud behaves differently from Google

Microsoft Ads click fraud tends to show up in different places than it does on Google Ads, for three structural reasons.

The first is reach. Microsoft Advertising serves across Bing, Yahoo, AOL and a network of syndicated search partners. Microsoft’s own exclusion documentation makes the boundary explicit: for Search campaigns you cannot block your ads from serving on Yahoo search and Microsoft search traffic, including Bing and AOL. You can only exclude the audience side. That is a narrower set of controls than Google gives you over its own partner network, which we covered in our guide to Google Search Partners.

The second is the Microsoft Audience Network. This is native display inventory across MSN, Microsoft Edge, Outlook.com and third-party publisher sites, and Search campaigns can be opted into it. Audience inventory is a fundamentally different traffic mix from search results. A click from someone typing “emergency plumber near me” into Bing and a click from a native ad unit at the bottom of a news article are not remotely the same intent, yet both land in the same campaign report. If your Microsoft Advertising costs rose without a matching rise in enquiries, checking whether audience ads are switched on is one of the first things worth doing.

The third is cost per click. Microsoft Advertising is generally cheaper than Google Ads for the same keywords, which cuts both ways. Cheaper clicks mean a fraudulent click costs you less individually. They also mean a smaller budget disappears in fewer clicks than you might expect on a high-value term, and the competitive pressure that drives deliberate sabotage still exists in expensive local trades. If a rival is prepared to click your ads, they are unlikely to stop at one platform. Our guide to working out whether competitors are clicking your ads uses Google Ads examples, but the investigation method transfers directly.

What you can actually block yourself in Microsoft Advertising

Microsoft Advertising gives you four native exclusion controls. They are worth setting up properly, and it is worth being clear-eyed about what each one can and cannot do. All of the specifics below come from Microsoft’s own documentation on preventing ads from showing to certain people.

IP address exclusions. You can block specific IP addresses from seeing your ads, but only at campaign level, never at ad group level. You are capped at 100 IP addresses or ranges per campaign, and only IPv4 addresses are supported. The last octet can be a wildcard, so 203.0.113.* blocks that whole block of 256 addresses. For comparison, Google Ads allows up to 500 exclusions per campaign, so Microsoft’s list fills up considerably faster. Our older walkthrough on manually blocking IP addresses in Google Ads covers the same logic if you want to see the Google equivalent.

Website exclusions. You can exclude up to 2,500 URLs from the Microsoft Advertising Network. Each URL needs a domain name and can include one subdomain and a maximum of two directories. Ad-group-level exclusions override campaign-level ones. As noted above, Search campaigns cannot block core Microsoft and Yahoo search traffic, and Audience campaigns cannot block Microsoft-owned sites such as Bing, MSN and Outlook.com.

App exclusions. If your ads are appearing in mobile apps you would rather avoid, run the Website URL (Publisher) report, add the Mobile Bundle column, copy the app identifier and add it to your website exclusion list. This is genuinely useful and almost nobody does it.

Location exclusions. You can exclude countries, regions, states, cities, metro areas and postal codes at campaign or ad group level. One limitation catches local businesses out: you cannot exclude using radius targeting, only the named location types.

Set all four up and you have a meaningful baseline. What you will run into is the arithmetic problem. Manual IP exclusion assumes the person or bot wasting your money keeps the same IP address, and that you will spot each new one, and that you will not exhaust your 100 slots. Residential proxies and rotating mobile IPs make that assumption shaky. This is the same wall Google Ads advertisers hit, and it is why our technical guide to detecting click fraud leans on behavioural patterns rather than addresses.

The signs of Microsoft Ads click fraud worth watching for

The warning signs on Microsoft Advertising look much like the ones on any other pay-per-click platform. Clicks rising while calls and form fills stay flat. A low-quality click rate that is far higher on one campaign than the rest. Sessions in your analytics that last a handful of seconds with no scrolling. Traffic from towns you do not serve, on a campaign that is supposed to be tightly targeted. Budget that runs out noticeably earlier in the day than it used to. Repeat visits from the same narrow set of networks.

None of these proves fraud by itself, which is the honest position and the one the ClickGuardian click fraud statistics page takes on industry claims generally. What they do is tell you where to look. Our post on the seven signs a campaign is under attack covers the investigation in more depth.

For context on scale, the Imperva and Thales Bad Bot Report found that automated traffic accounted for 51% of all web traffic in 2024, the first time bots overtook humans, with 37% classed as malicious. Integral Ad Science found campaigns running without anti-fraud technology hit a fraud rate of 10.9%, roughly fifteen times the rate of protected campaigns. Both figures are on the ClickGuardian statistics page with their original sources. Nothing about those numbers is specific to Google, and there is no reason to assume the bot half of the internet politely avoids Bing.

What to do if you think you have been charged for invalid clicks

If you believe Microsoft Advertising has charged you for invalid clicks, Microsoft’s stated route is to contact support directly. There is no self-service claim form equivalent to the one Google Ads offers, which we cover in our guide to claiming a Google Ads invalid click refund.

Go in with evidence rather than a suspicion. Pull the date range, the affected campaigns, the low-quality click figures from your report, your conversion rate over the same window compared with a normal period, and anything from your own web analytics or server logs showing repeated visits from the same sources. Microsoft says it flags suspected cases, examines the affected accounts and issues credits where appropriate. A specific, documented request gives that process something to work with.

Set your expectations sensibly. Platform credits are usually partial and slow, and they are a refund mechanism rather than a prevention one. Getting money back for last month does not stop next month.

Where automated protection fits

Microsoft’s own filtering handles the obvious end of the problem. Known bots, crawlers, clearly mechanical clicking patterns. What it is not designed to do is learn the specific pattern of the specific people and systems wasting your specific budget, then act on it in real time.

That is the gap ClickGuardian is built for. ClickGuardian scores every visitor from your Microsoft Advertising and Google Ads campaigns on network signals, behaviour and repetition, and identifies the sources that keep failing. On Google Ads those sources are excluded automatically. Microsoft’s advertising API does not let any vendor push IP exclusions, so on Microsoft Advertising the offending IPs are surfaced in your dashboard instead, ranked by the budget they are wasting and trimmed to fit within the 100-per-campaign limit. Pasting them in takes a couple of minutes, and because detection works from device and behaviour signals rather than a static address list, what you are handed is the current worst offenders rather than a stale history. The Microsoft Ads protection page covers how that works in practice.

Whether that is worth paying for depends entirely on your numbers. A business spending £400 a month on Microsoft Advertising at modest cost per click has a much smaller problem than an emergency trade spending £4,000 on terms that cost £15 a click, which is why our industry pages for trades such as plumbing exist. Work out your own exposure with the ROI calculator before deciding. If the sums do not justify it, the exclusion settings above are free and genuinely worth an hour of your time.

If you run both platforms, it is also worth doing a proper review of the larger account first. Our ten-step Google Ads audit is designed to be run in an afternoon, and most of the checks in it translate cleanly to Microsoft Advertising.

Frequently Asked Questions

Does Microsoft Advertising have click fraud?

Yes. Microsoft Advertising is exposed to click fraud in the same way as any pay-per-click platform. Microsoft grades every click as standard-quality, low-quality or invalid, filters what it can identify, and only bills advertisers for standard-quality clicks. Sophisticated invalid traffic, competitor clicking and human click farms can still get through that filtering, exactly as they do on Google Ads.

How do I see invalid clicks in Microsoft Ads?

Microsoft Advertising does not show invalid click data by default. Open the Report Builder, create a performance report, and use the column modifier to add the Low-quality clicks and Low-quality click rate (%) metrics. Run it at campaign and ad group level over ninety days or more, and compare campaigns against each other rather than against an external benchmark. Note that clicks Microsoft later credits as invalid still appear in your reports as standard-quality clicks.

Does Microsoft refund invalid clicks?

Microsoft Advertising says it credits accounts automatically when it suspects invalid clicks generated by search engine robots, automated clicking tools or other fraudulent means, and that bills are adjusted when a charged click is later judged low-quality or invalid. If you think you have been charged for invalid clicks that Microsoft did not catch, the route is to contact Microsoft Advertising support with dates, campaigns and supporting data. There is no self-service claim form.

How many IP addresses can I block in Microsoft Ads?

Microsoft Advertising allows a maximum of 100 IP addresses or IP address ranges per campaign, added at campaign level only. Only IPv4 addresses are supported, and only the final octet can be a wildcard, so 203.0.113.* covers that range of 256 addresses. Google Ads allows up to 500 exclusions per campaign by comparison, so the Microsoft list fills up faster and needs more careful curation.

Should I turn off the Microsoft Audience Network?

It depends on what your reports show rather than on a general rule. The Microsoft Audience Network serves native ads across MSN, Microsoft Edge, Outlook.com and third-party publisher sites, which is a very different traffic mix from search results. Run the Website URL (Publisher) report to see where your spend is actually going and what it converts at. If audience placements are taking a meaningful share of budget and producing few enquiries, reducing or excluding them is a reasonable step. Some advertisers do see genuine results from it, so check your own data before switching it off.


Last updated: September 2026. For the fundamentals that apply on every platform, start with what is click fraud? and what is invalid traffic?, then see how the same problem plays out across Google, Microsoft and Meta and how AI bots drain ad budgets. The sourced numbers are on the click fraud statistics page, and the click fraud glossary covers the vocabulary used here. To estimate what invalid clicks are costing your own campaigns, use the ClickGuardian ROI calculator.

microsoft ads click fraud bing ads click fraud microsoft advertising invalid clicks low quality clicks microsoft ads microsoft ads ip exclusions microsoft audience network traffic quality Microsoft Ads click fraud PPC
Dan Slay

Written by Dan Slay

Founder

Dan Slay is the founder of ClickGuardian. After experiencing click fraud first-hand running Google Ads campaigns, he built ClickGuardian to give businesses the tools to detect and block fraudulent clicks in real-time. Dan oversees product strategy and growth, and is passionate about helping advertisers get more from their ad spend.

Enjoyed this article?

Get weekly PPC protection tips and fraud alerts delivered to your inbox.

No spam. Unsubscribe anytime.