To create a Google Analytics account, sign in at analytics.google.com with a Google account, click Start measuring, name the account, create a GA4 property, add a web or app data stream, and install the Google tag that carries your G- Measurement ID. GA4 is the only current version: Universal Analytics stopped processing data in 2023 and its data became inaccessible on July 1, 2024.
Setup choices such as the property time zone, currency and data retention shape every report afterward, so it pays to get them right the first time. A clean Google Analytics installation also makes integrations with Google Ads, BigQuery and Looker Studio more reliable.
For developers sending events from a backend (for example Go services using the Measurement Protocol), the property and data stream you pick at creation decide where those events land, because the protocol requires the stream's Measurement ID and an API secret. This guide covers the account, property and data stream hierarchy; web, iOS and Android streams; enhanced measurement; cross-domain tracking; user permissions; and verification with DebugView and Realtime reports.
GA4 is event-based: every interaction, including page views, is recorded as an event with parameters. Conversions are now called key events. Coming from Universal Analytics, expect a learning curve, but the model is more flexible once it clicks.
This is a setup guide, not a measurement strategy guide; the goal is clean data from day one.
Visit analytics.google.com, sign in with your Google account, and click Start measuring. If you already have an account, open Admin and click Create > Account. Use a Google account that will outlive your role at the company, ideally a shared Workspace identity.
Enter an account name that reflects your organization, not a specific website. An account can hold up to 2,000 properties, so pick something like Acme Corporation rather than acme.com. Configure data sharing settings on this same screen.
Properties are the actual data containers. Name yours after the website or app, set your reporting time zone, and pick your currency. These settings affect every report and cannot be changed retroactively without losing comparability with historical data.
Choose Web, iOS, or Android. For websites, enter the full domain and a stream name. Google generates a Measurement ID starting with G- that you will paste into your site code or tag manager container.
Install the GA4 tag using Google Tag, Google Tag Manager, a CMS plugin, or a server-side container. Verify the install in DebugView and Real-Time reports within minutes of deploying the code.
Set data retention to 14 months, enable Google Signals if appropriate, mark your key events as conversions, and invite your team. Run final QA across browsers, devices, and incognito sessions before announcing go-live.
GA4 organizes data in three levels: an account (the top-level container for your business), a property (the container for the reports built from your data), and a data stream (the website or app that sends events into the property).
Understanding the GA4 hierarchy is the single biggest mental shift required when creating a new Google Analytics account today. The structure goes account, then property, then data stream, and each level has its own settings, permissions, and limits. An account is the top-level organizational container, typically tied to a single business entity. A property is the actual analytics database where your data lives. A data stream is the source feeding events into that property, whether it is a website, an iOS app, or an Android app.
Most small businesses need exactly one account, one property, and one to three data streams. A startup with a marketing site and a single mobile app, for example, would create one property and add three streams: one web, one iOS, one Android. All three streams report into the same property, giving you unified cross-platform user analysis. This is a major improvement over Universal Analytics, which tracked web and app in separate properties.
Larger organizations or agencies sometimes need multiple properties under one account. Common reasons include strict data isolation between brands, separate billing for BigQuery exports, or distinct legal jurisdictions (a European property versus a U.S. property for GDPR reasons). Google documents a ceiling of 2,000 properties per account and 50 data streams per property (no more than 30 of them app streams). The property ceiling is rarely a constraint, but the stream limit can be for businesses with many localized sites.
Pay particular attention to the time zone and currency settings on the property. The time zone determines when a "day" starts and ends in every report. If your business is U.S.-based and reports against U.S. business hours, set the property time zone to your local zone, not UTC. The currency setting affects how purchase events are aggregated when your site accepts multiple currencies. Both settings can be edited later, but changing them does not retroactively rewrite historical data, so day-over-day comparisons will look weird across the boundary.
Data streams have their own configuration menu where you set enhanced measurement, define internal traffic rules, configure unwanted referrals, set the cross-domain list, and manage the measurement protocol API secret. The measurement protocol secret is what lets server-side code, including Go backends, send events directly to GA4 without going through a browser. Treat that secret like a password and store it in your secrets manager, not in source control.
One last note on hierarchy: there is no concept of "views" in GA4 the way there was in Universal Analytics. Data filters (internal traffic and developer traffic) are available in standard GA4, while subproperties and roll-up properties are Analytics 360 features. For the free tier, every event collected into a property is visible to anyone with property-level access. Plan your permissions accordingly.
| Level | What it is | What you configure there | Documented limit |
|---|---|---|---|
| Account | Top-level container for one or more properties; tied to a business or organization | Account name, data-sharing settings, account-level user access, change history | Up to 2,000 properties per account; up to 100 accounts per user |
| Property | Container for the reports and analysis built from the data you collect | Time zone, currency, data retention, key events, custom definitions, data filters, product links (Google Ads, BigQuery, Search Console) | Up to 50 data streams per property; 50 event-scoped and 25 user-scoped custom dimensions (standard) |
| Data stream | Flow of data from one website, iOS app, or Android app into the property | Measurement ID (G-XXXXXXXXXX), enhanced measurement, cross-domain settings, unwanted referrals, Measurement Protocol API secrets | No more than 30 of the 50 streams can be app streams |
Sources: Google Analytics Help, "Google Analytics hierarchy" (support.google.com/analytics/answer/9303323) and "About custom dimensions and metrics" (support.google.com/analytics/answer/10075209).
Prepare for the Google Analytics exam with our free practice test modules. Each quiz covers key topics to help you pass on your first try.
A web data stream collects events from a browser-loaded website. During creation you enter the website URL and a stream name, then Google generates a Measurement ID prefixed with G-. Enhanced measurement is on by default, automatically tracking page views, scrolls, outbound clicks, site search, video engagement, and file downloads. Toggle individual events off if they create noise for your business model.
Web streams are where you configure cross-domain tracking, unwanted referral exclusions, and internal traffic filters. If your checkout sits on a different domain than your marketing site, add both domains to the cross-domain list during stream creation. Forgetting this step is the most common cause of inflated direct traffic and broken funnels in newly created GA4 properties tracking website hits.
iOS streams require the Firebase SDK because GA4 mobile measurement runs through Firebase under the hood. During stream creation you provide your app bundle ID, app name, and App Store ID. Google generates a Firebase project automatically if one does not exist, and you download a GoogleService-Info.plist file to embed in your Xcode project. SwiftUI and UIKit projects both use the same SDK.
App Tracking Transparency rules from Apple mean iOS streams collect less attribution data than web streams by default. Plan for SKAdNetwork integration and modeled conversions to fill the gap. Check the Google Analytics release notes before assuming iOS features behave the same as they did months ago.
Android streams also flow through Firebase. You provide the package name, app nickname, and optionally a debug signing certificate SHA-1 hash for testing. The setup wizard generates a google-services.json file that lives in your app module. Gradle plugins handle the rest of the wiring during build. Most Android crashes related to GA4 trace back to a missing or stale google-services.json file.
Combined with web stream data in the same property, you get a unified cross-platform user count that was impossible in Universal Analytics. Use the User-ID feature to stitch sessions across signed-in devices for the cleanest possible journey reports across platforms.
GA4 defaults user-level and event-level data retention to just 2 months. This means explorations, funnels, and custom segments older than 60 days will be unavailable. Go to Admin > Data Settings > Data Retention and change it to 14 months on day one. This setting only affects exploration data, not standard reports, but for serious analysis it is essential.
User permissions in a newly created Google Analytics account follow a five-role hierarchy: Viewer, Analyst, Marketer, Editor, and Administrator. The role you assign determines what a user can do at the account or property level. Administrator is the only role that can manage users and delete properties, so reserve it for one or two trusted owners. Editor can change configuration but not manage users. Marketer can create and edit audiences, events and key events. Analyst can create and share explorations and dashboards. Viewer is read-only.
A common mistake during initial setup is making everyone an Administrator because it is faster than thinking about roles. This creates real risk: an Administrator can delete a property and its data. Deleted items go to the Trash can for a limited time before they are permanently removed. Apply least privilege from the start. For most teams, a small number of Administrators with everyone else as Editor, Marketer, Analyst or Viewer is the right shape.
Permissions cascade. An Administrator at the account level is automatically an Administrator on every property and every data stream beneath it. You can also assign roles at the property level only, which is useful when an agency needs access to one client property but not the rest of your accounts. Subproperties and roll-up properties exist only in Analytics 360 and let you scope access to a subset of data.
Two special data restrictions are worth knowing about: No Cost Metrics and No Revenue Metrics. These are toggles that hide cost and revenue figures from specific users even if their role would otherwise show them. They are perfect for agencies whose junior analysts should see traffic but not the client's media spend, or for retail organizations where store managers should see store-level traffic but not corporate revenue totals.
Audit your user list every quarter. Former employees and ex-agency contractors keep access far longer than they should at most companies. Google does not automatically remove users when their email domain becomes inactive. Build a recurring reminder, ideally tied to your normal access review for other SaaS tools, and prune aggressively.
For developer teams working on server-side measurement protocol calls or BigQuery exports, prefer service accounts where possible. A service account does not have a human owner who might leave the company. Bind the service account to a specific Cloud project, grant it only the analytics roles it needs, and rotate its credentials regularly. This pattern is the gold standard for Go, Python, and Node backends that push events into GA4 outside the browser.
One last permissions tip: linked products like Google Ads, Search Ads 360, Display & Video 360, BigQuery, and Search Console each have their own access settings. Granting someone Editor in GA4 does not grant them access to the linked Google Ads account. Coordinate across product admin consoles whenever you onboard or offboard a teammate to avoid stranded credentials or unexpected data exposure.
Once your account is collecting clean data, the next layer of configuration unlocks the real power of GA4. Custom dimensions and custom metrics let you register event parameters and user properties so they appear in standard reports and explorations. Standard properties allow 50 event-scoped custom dimensions, 25 user-scoped custom dimensions, and 50 custom metrics (Analytics 360 raises these to 125, 100 and 125). Register them sparingly and name them consistently using a documented convention like snake_case_with_prefix.
The BigQuery export is the single highest-value integration you can enable in a free GA4 account. Linking your property to a Google Cloud project sends every raw event, with full parameter detail and zero sampling, into BigQuery. You can choose a daily export, a streaming export, or both. Linking is free, but BigQuery storage and query usage can incur Google Cloud charges beyond the free tier, and standard properties have a daily export event limit.
Linking Google Ads to your GA4 property unlocks two huge capabilities: audience sharing and conversion import. Audiences built in GA4 (for example, "users who added to cart but did not purchase") flow into Google Ads as remarketing lists. Key events marked as conversions in GA4 can be imported into Ads for bidding optimization, although Google now recommends sticking with native Ads conversions for the cleanest signal. Check the Google Analytics release notes for integration changes.
Search Console linking adds organic search query data to GA4 reports. This is the only way to see which Google search queries drive traffic to which landing pages inside your analytics tool. Once linked, Search Console reports appear in the GA4 navigation after a short delay. It is worth doing during initial setup.
If you serve users in the EEA or UK, implement Consent Mode through your consent management platform (CMP) and verify that consent signals reach GA4. When consent is denied, Consent Mode can send cookieless pings that GA4 uses for modeling; without it, users who decline are simply not measured, which can leave gaps in your reporting.
Server-side tagging is the most advanced configuration option. Instead of loading GA4 directly in the browser, you route hits through a tag manager container running on your own Google Cloud Run or App Engine instance. This gives you privacy benefits, smaller browser payloads, and the ability to enrich events with first-party data before they reach Google. It requires a hosting environment (such as Google Cloud) that carries its own cost, so it is usually a second-phase project rather than part of the initial account setup.
Finally, document your account configuration. A simple Google Doc or Notion page listing your property IDs, measurement IDs, custom dimensions, key events, linked products, and team contacts saves the next analyst on your team weeks of detective work. Update it whenever you change anything. Future you will be grateful.
Now that the account is created and the advanced integrations are wired up, the final phase is operational hygiene: practices that keep your data trustworthy over months and years. The first habit is naming. Every custom event, parameter, dimension, audience, exploration, and shared asset should follow a written naming convention. Without one, you end up with three versions of "purchase_complete," "purchaseComplete," and "PurchaseComplete" in the same property, and your reports become impossible to trust.
The second habit is regular audits. Once a quarter, walk through Admin and ask: are time zone and currency still correct? Has anyone new joined or left? Are key events still mapped to the right business outcomes? Are custom dimensions still being populated? Has data retention reverted? Settings can change after product updates, so a calendar reminder is worth more than trust.
The third habit is debug discipline. The DebugView report in GA4 shows events from devices marked as debug mode in real time. Use the Google Analytics Debugger Chrome extension or pass debug_mode=true in your tag configuration to enable it. Every time you ship a tracking change, walk through the user flow with DebugView open and verify each event fires with the right parameters. Skipping this step is the most common cause of broken reports in production.
The fourth habit is monitoring. Set up email alerts in the Custom Insights area for anomalies that matter to your business: a 40% drop in conversions day-over-day, a sudden spike in 404 errors, an unusual traffic source. GA4's machine learning catches most anomalies automatically, but explicit alerts on your top three or four KPIs ensure you hear about problems within hours, not weeks.
The fifth habit is documentation. The single highest-ROI hour you will spend in your first month is writing a one-page reference doc that lists your property ID, your measurement ID, your data layer schema, your event taxonomy, and the contact owner for each integration. Pin it in your team workspace. Update it whenever something changes. New hires will thank you and external auditors will move faster through your account.
The sixth habit is education. The certification exam is a useful forcing function for filling knowledge gaps. Even if you do not need the credential professionally, working through practice questions exposes parts of the interface you have never opened. Many strong analysts pursue the google data analytics certification specifically to ensure their team has a shared baseline understanding of the product, not because clients ask to see badges.
The final habit is staying current. GA4 changes often. New features, reports and deprecations appear regularly. Subscribe to the official Google Analytics release notes and skim them periodically so your configuration does not drift from current best practice.