Microsoft UET Consent Mode communicates a visitor's consent choice to the Universal Event Tracking tag used by Microsoft Advertising, formerly Bing Ads. It controls advertising cookie access through the ad_storage setting. It does not collect consent itself or replace your consent banner.
The implementation decision is whether to block UET until consent or allow it to run with a denied state. This guide explains that choice and provides a practical review process for your CMP, tag manager and conversion events.
What Microsoft requires from advertisers
Microsoft announced a 5 May 2025 deadline for advertisers to send consent signals for website visits from the European Economic Area, the United Kingdom and Switzerland. This is an existing platform requirement, not a future deadline or a new statutory commencement date. Microsoft supports UET Consent Mode and an alternative integration with the IAB Transparency and Consent Framework. Microsoft's consent-signal announcement.
The relevant location is the visitor's location. An advertiser based elsewhere can still receive affected traffic. Microsoft's current FAQ warns that missing signals can disrupt UET conversion tracking and remarketing. It also instructs advertisers to choose Consent Mode or TCF rather than implement both simultaneously. Microsoft's UET consent FAQ.
Record which integration supplies the authoritative choice. A CMP integration, a GTM template and a custom script should not independently send contradictory states to the same tag.
Choose Basic or Advanced UET Consent Mode
| Approach | Before advertising consent | Implementation decision |
|---|---|---|
| Basic | UET is blocked; it sends no data before consent | Use when your approved design requires UET to remain inactive until permission is obtained |
| Advanced | UET runs with a denied state; reduced data can still be transmitted | Review the actual requests and approve the processing before enabling it |
Microsoft recommends Advanced as a technical approach to measurement. That recommendation does not determine the lawful basis for your site's processing. Its February 2026 guidance also says Advanced is not strictly required to receive modelled conversions. Avoid promises that enabling it recovers every lost conversion or guarantees a particular uplift. Microsoft's Advanced Consent Mode guidance.
For a UK deployment, the ICO explains that storage and access rules extend beyond cookies and can apply even where information is anonymous. “Cookieless” is therefore insufficient as a legal assessment. Review device access, transmitted information, purposes and applicable exceptions. ICO guidance on cookies and similar technologies.
For California traffic, assess the relevant sale or sharing and opt-out obligations separately. An advertising consent variable does not establish that every downstream transfer is permitted. See CCPA sale versus sharing.
Understand the UET consent states
The documented UET control is ad_storage, using the strings granted and denied.
- Granted: UET may read and write first-party and third-party cookies.
- Denied: first-party UET cookies are not read or written; third-party cookies are not written. Microsoft's documentation permits third-party cookie reads for fraud and spam prevention, rather than advertising.
Microsoft documents a denied default where consent enforcement applies in the EEA, UK and Switzerland, and a granted fallback in most other countries when no setting is supplied. Set the intended state explicitly instead of relying on geography or an omitted value. Microsoft's UET setup documentation.
Do not interpret denied as a network kill switch. If your requirement is no Microsoft Advertising requests before consent, validate a Basic implementation against that requirement.
Connect your CMP and tag manager
Start by locating every UET deployment: the GTM container, site code, ecommerce integration and any plugin that may install another tag. Record the tag IDs and the conversion goals they support.
Next, write down the mapping from the actual choice shown to visitors to the Microsoft advertising permission. An analytics-only choice should not silently become an advertising grant. The notice and CMP categories must describe what the mapping allows.
For Advanced implementations, Microsoft's current guidance calls for UET to load early, with denied established for the initial page view, and an explicit granted update once applicable permission exists. Its recommended GTM route uses the official Microsoft Advertising UET template. Check the actual CMP-to-template connection; simply placing both products in the same container does not prove that it works. Microsoft's Advanced setup guidance.
Microsoft's template documentation distinguishes Inherit initial consent from Enable consent updates. These address different moments: the state already available when UET starts, and later changes. Review both against your CMP's timing, especially where a saved preference is restored before UET loads. Microsoft's GTM consent integration documentation.
For Basic, keep the tag blocked until the relevant permission is available, then initialise UET with the correct consent state. Test the first permitted conversion event as well as the page view.
A useful implementation specification states:
- Which component decides the initial permission.
- Which component communicates it to UET.
- How later changes reach the tag.
- How a returning visitor's saved choice is restored.
- What happens when the CMP fails or cannot resolve a choice.
Test the whole visitor journey
Use a fresh browser profile for the initial tests. Record the page, region, CMP configuration, tag version, choice and observed result. Repeat on the checkout or lead-completion route rather than checking only the homepage.
Microsoft provides UET Tag Helper for inspecting events. Its setup documentation identifies the asc consent parameter and a dashboard consent-signal status. Check event-level evidence alongside those summaries. Microsoft's validation instructions.
| Test | Evidence to collect |
|---|---|
| New visitor, no interaction | Whether UET is blocked or running as designed; the first request's consent state and storage changes |
| Reject advertising | Subsequent page views and custom events retain the rejected choice |
| Accept advertising | The permission reaches UET before the events intended to use it |
| Accept analytics only | Advertising remains denied or blocked under the chosen implementation |
| Withdraw permission | Later events and storage behaviour reflect the change without requiring a reload |
| Return with a saved choice | The correct state is restored on landing pages and deep links |
| Navigate within a single-page application | Route changes do not reset consent or introduce duplicate events |
| CMP delayed or unavailable | There is no unintended grant while a choice is unresolved |
Inspect network requests and browser storage together. A denied label with unexpected advertising identifiers needs investigation. Identify the script responsible before changing settings: a duplicate tag or separate integration can obscure which component generated the traffic.
For conversion testing, verify the event name and goal configuration separately from consent. UET events and Microsoft Advertising conversion goals work together, and an event being sent does not alone prove an attributed conversion should appear. Microsoft's Tag Helper can also test goal events. Microsoft's conversion-tracking documentation.
Troubleshoot common implementation failures
Granted appears only after a second banner interaction. Compare the CMP's stored-choice restoration with UET initialisation. The update may have occurred before the tag started listening. Review the template's initial-consent and update options.
Google shows consent correctly, but Microsoft does not. Follow the signal into the UET integration and inspect a Microsoft request. A correct Google tag state is not evidence that the UET connection has been configured.
Advanced is configured, but UET never loads before acceptance. Check the CMP's automatic blocking and GTM triggers. Decide whether the intended design is Basic or Advanced before changing either.
Requests are duplicated. Compare tag IDs and initiating scripts. A platform app and a GTM deployment may both be active. Consolidate ownership and retest all goals.
These are diagnostic starting points. Preserve the failing request and event sequence so that a configuration change can be assessed against the same test.
Frequently asked questions
Does UET Consent Mode make a website GDPR compliant?
No. It transmits a technical choice. You still need appropriate notices, valid consent where required, correct data handling and an implementation that matches the choice made.
Does UET Consent Mode also configure Microsoft Clarity?
Microsoft's UET documentation requires Clarity consent to be configured separately when the UET-Clarity integration is used. Review Microsoft Clarity consent and test its requests separately.
Is Google Consent Mode v2 the same integration?
No. The official UET GTM template can connect to GTM consent information, but UET has its own implementation. Use the cross-platform consent signals guide to plan the mapping between systems.
Should every website choose Advanced?
Choose the approach that matches your approved processing and measurement requirements. Compare the behaviour you can verify, including what is sent before a choice, rather than treating a platform recommendation as universal legal permission.
Related implementation guides
- Basic versus Advanced Google Consent Mode explains the corresponding Google decision.
- Consent Mode and consent signals brings together the platform guides.
- Request a consent audit to review the behaviour of an existing implementation.
