Web Analytics with Google Analytics 4Measurement strategy before tools · Lesson 3 of 20

Setting up a GA4 property the right way

Article · 10 min · 8 min lecture

Video lecture

Setting up a GA4 property the right way

14 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 14

GA4 property setup

  • Accounts, properties, data streams
  • Day-one configuration
  • 2026: data controls and Advisor
  • A 30-minute audit

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Structure: accounts, properties and data streams

GA4 organizes data in three levels:

  • Account — usually one per organization (the legal entity that owns the data).
  • Property — a reporting unit, typically one per brand or product. A property can combine web and app data.
  • Data stream — a source of data feeding the property: a website, an iOS app or an Android app.

Agencies should keep each client's property inside the client's own account and be granted access, not the other way round. Ownership matters when relationships end.

A common question is whether to use one property or several. Use one property when the same users move across domains or apps you want to analyze together (for example shop.example.com and blog.example.com). Use separate properties for genuinely separate businesses or brands with different audiences and owners.

The configuration checklist

Work through these settings on day one; several cannot fix historical data later.

SettingWhat to doWhy it matters
Time zone and currencyMatch the business's reporting conventionsDaily totals and revenue depend on it
Data retentionReview; standard properties default to 2 months and can be raised to 14 monthsControls how far back explorations can look at event-level data
Enhanced measurementReview each option (page views, scrolls, outbound clicks, site search, video, file downloads, form interactions)Free events, but some can double count or misfire
Internal trafficDefine internal IP rules, test, then activate the filterKeeps staff visits out of reports
Developer trafficUnderstand the developer traffic filter used with debug modeKeeps QA hits out of production data
Unwanted referralsList payment gateways and SSO domainsStops checkout returns being credited as "referral"
Cross-domain measurementConfigure when journeys span domainsPreserves the session across domains
Key eventsMark the events agreed in your tracking planPowers conversion-focused reporting
Product linksLink Google Ads, Search Console, and BigQuery if usedEnables richer analysis and audience sharing
AccessGrant least-privilege roles to named individualsSecurity and accountability

Enhanced measurement: helpful but check it

Enhanced measurement automatically collects events such as scroll (when a user reaches around 90% depth), click for outbound links, view_search_results, file_download and video engagement for embedded YouTube videos. Review these carefully:

  • Form interactions can fire on forms you do not care about, or miss forms built with unusual frameworks. Many teams disable it and implement form tracking explicitly.
  • Site search relies on query parameters such as q or s; add your site's parameter if it differs.
  • Page views on history changes are useful for single-page applications but can double count if your developers also send manual page views.

Filters and data hygiene

GA4 data filters (internal and developer traffic) are applied permanently once active — filtered data is not recoverable. Always create a filter in testing state first, check that the test dimension shows the expected traffic, then activate.

For referral spam or bot traffic, GA4 excludes known bots automatically, but you should still watch for suspicious spikes (for example many sessions from one city with zero engagement).

Worked example: a Pakistani fashion brand with a hosted checkout

An online clothing brand in Karachi runs its storefront on its main domain but payment happens on a third-party gateway's domain before redirecting back. Without configuration, every returning buyer starts a new session attributed to the gateway as a referral, and paid campaigns look like they generate no sales. The fix:

  1. Add the gateway domain to unwanted referrals.
  2. Confirm the purchase event fires on the store's confirmation page with a unique transaction_id.
  3. Compare channel revenue for a week before and after — paid and organic channels should now receive the credit.

Access and governance

Use roles deliberately: Administrator for a very small number of owners, Editor for implementers, Analyst or Viewer for report users. Remove access when people leave. Keep a short change log (date, change, person, reason) — GA4's own change history helps, but a human-readable log explains why.

What changed in 2026: data controls and AI in the interface

Two changes affect setup decisions this year:

  • Google signals and Google Ads data controls. Google announced that from June 15, 2026, the Google signals setting in GA4 controls only the association of Analytics data with signed-in user information for behavioral reporting. For linked properties, Google Ads settings control Google Ads data (including data shared from Analytics), and Ads cookie and identifier collection is governed by consent mode, specifically ad_storage. Review your Ads links, consent configuration and privacy notice together, not in isolation. Check Google's current "Updates to Google Analytics data controls" help page for the latest detail.
  • Analytics Advisor. Google has added a Gemini-powered, conversational assistant inside GA4 (Ask Advisor, in beta in 2026) that answers plain-language questions about your property. Treat its answers as a starting point and verify them in reports (module 5 and module 7 cover this).

Hands-on: a 30-minute setup audit script

Use this sequence on any property you inherit. Record answers in a sheet with a red/amber/green column:

ADMIN > Account/property details: owner is the client? time zone, currency correct?
ADMIN > Data collection and modification > Data retention: 2 or 14 months? documented reason?
ADMIN > Data streams > Web > Enhanced measurement: each toggle reviewed? form interactions intended?
ADMIN > Data streams > Configure tag settings: internal traffic defined? unwanted referrals include gateways/SSO?
         cross-domain configured where journeys span domains?
ADMIN > Data filters: internal/developer filters active? were they tested first?
ADMIN > Events > Key events: only true business outcomes?
ADMIN > Product links: Google Ads, Search Console, BigQuery linked as intended?
ADMIN > Property access management: named users only, least privilege, no ex-staff/ex-agencies?
ADMIN > Data collection: Google signals and data controls reviewed against the June 2026 changes and consent setup?

You can also pull property settings programmatically with the Google Analytics Admin API, or via Google's experimental Google Analytics MCP server, which exposes read-only tools such as property details and account summaries to AI assistants. Use read-only credentials.

Second worked example: a UAE clinic group

A healthcare group in Abu Dhabi and Dubai runs one website per clinic brand. The audit finds the properties under a former agency's account, retention at two months, no internal-traffic filter (staff check appointment pages all day) and no cross-domain setting for the shared booking domain. The fix plan: transfer ownership to the group's own account, raise retention with a documented reason, test and activate an internal filter, configure cross-domain measurement for the booking domain, and restrict access to named staff. The team also records in the change log that historical data before the fixes is not comparable.

Common mistakes

  • Creating the property under an agency or freelancer's personal account.
  • Leaving data retention at the default and discovering too late that year-on-year explorations are impossible.
  • Activating an internal-traffic filter without testing it.
  • Forgetting unwanted referrals for payment gateways.
  • Marking dozens of events as key events, making "conversions" meaningless.

Activity preview

After this lesson, audit a GA4 property you have access to against the checklist above and note each gap along with its business impact.

Key takeaways

  • Account = organization, property = reporting unit, data stream = source of data.
  • Clients should own their GA4 accounts; agencies are granted access.
  • Review retention, filters, unwanted referrals and cross-domain settings on day one.
  • Test data filters before activating — filtered data cannot be recovered.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Paid campaigns show almost no revenue, while a payment gateway appears as a top referral source. What is the likely fix?
  2. Why should you test a GA4 internal-traffic filter before activating it?
  3. An agency sets up a client's GA4 property. Who should own the account?

Put it into practice

Audit a GA4 property against the configuration checklist and list each gap, its business impact and the fix, in priority order.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.