# Tag Manager consent settings: what "Not set" means

Every tag in Google Tag Manager has a consent setting, and most are left on Not set. What built-in and additional checks do, plus a 20-minute audit.

_The TagSentry team · September 10, 2026 · https://tagsentry.ai/blog/gtm-consent-settings-not-configured_

> **The short answer:** In Tag Manager, each tag has a consent setting under Advanced Settings. "Not set" means Tag Manager won't hold the tag for any consent beyond what the tag checks by itself. Google's own tags check Consent Mode anyway. Other vendors' tags don't, so a Meta or TikTok tag on "Not set" fires whatever the visitor chose.

## Where the setting lives

Open any tag in Tag Manager, then Advanced Settings, then Consent Settings. You'll see three options:

- **Not set**: the default for most tags.
- **No additional consent required**: you've decided this tag doesn't need any.
- **Require additional consent for tag to fire**: pick which consent types (like `ad_storage`) must be granted first.

Above that, some tags show **Built-in consent checks**, a read-only list of what the tag already respects by itself.

## Built-in versus additional consent

People mix these two up a lot.

**Built-in checks** exist only on tags whose code understands Consent Mode. Google's own tags (the Google tag, GA4 events, Google Ads, Floodlight) have them. They'll adjust what they do based on `ad_storage`, `analytics_storage` and the rest without you configuring anything, as long as Consent Mode defaults are set early on the page.

**Additional checks** are Tag Manager holding a tag until a consent type is granted. You use them for tags that know nothing about Consent Mode, like Meta Pixel, TikTok, LinkedIn, Hotjar and most custom HTML.

| Tag type | Built-in checks | What to set |
|---|---|---|
| Google tag, GA4, Google Ads | Yes | Usually leave as is, Consent Mode handles them |
| Meta, TikTok, LinkedIn, Pinterest (template or custom HTML) | Usually no | Require additional consent, typically `ad_storage` |
| Hotjar, Clarity, session recording | No | Require `analytics_storage` |
| Chat widgets, A/B testing | Varies | Decide per tool, then set it explicitly |
| Strictly necessary (fraud, load balancing) | n/a | "No additional consent required", deliberately |

## Why "Not set" is a problem

"Not set" means nobody decided. For a Google tag that's mostly fine, because the tag checks by itself. For a Meta Pixel it means the tag fires on every page for every visitor, whatever they clicked.

It makes audits harder too. When every tag says "Not set", you can't tell which ones someone actually thought about.

## The 20-minute audit

1. **Turn on the consent overview.** In the container, go to Admin, Container Settings, and tick "Enable consent overview". A shield icon appears on the Tags list.
2. **Open the consent overview.** It groups tags into "Consent not configured" and "Consent configured". Start with the first group.
3. **Decide for each tag.** Is it Google's (built-in checks), is it necessary, or does it need `ad_storage` or `analytics_storage` first? Set it explicitly, even if the answer is "No additional consent required".
4. **Check the order of defaults.** Your [Consent Mode defaults](/blog/google-consent-mode-v2-explained) must be set before any tag runs, either by a script above the Tag Manager snippet or by a tag on the "Consent Initialization" trigger. A default set on "All Pages" is too late.
5. **Look for blocking triggers on Google tags.** If someone added "only fire when consent is granted" triggers to your GA4 or Google tag, you're probably losing page views you didn't need to lose. Let Consent Mode handle those.
6. **Test in preview, in two regions.** Check the Consent tab on the first event: the default state should be there before any tag fires. Then accept, and check it updated.
7. **Write down what you decided.** A short list of tag, purpose and consent type will save the next person hours.

> **Don't forget what's outside Tag Manager** Tag Manager's settings only cover tags in the container. A Meta Pixel pasted into your theme, a chat widget added by a plugin, or a script in your checkout settings won't appear in the consent overview at all. Check the page source too.

## The ordering problem, again

Plenty of "consent isn't working" threads come down to order. As one Tag Manager user put it: "the consent mode loads at the end of the events chain… it should activate before the page loads." If your consent tool runs as a tag in the container, check which trigger it uses. Consent Initialization is the trigger made for this.

## Keeping it right

The audit goes out of date the day someone adds a new tag. Someone on r/gdpr pointed out that many consent tools only rescan weekly or monthly, "so a new script or tag can slip through undetected for weeks." Put a recurring reminder on the calendar, or use [something that checks continuously](/monitoring).

## How TagSentry helps

With [Tag Manager connected](/docs/tag-manager), TagSentry reads every tag in your container, sorts each one by purpose, and shows you the consent settings it would change. Nothing changes in Tag Manager until you approve it, and every change is a new version there, naming the one it replaced. For trackers outside the container, we scan your live site.

## Sources

- [Google Tag Manager Help: Consent mode overview](https://support.google.com/tagmanager/answer/13695607?hl=en)
- [r/GoogleTagManager: consent mode loads at the end of the events chain](https://www.reddit.com/r/GoogleTagManager/comments/1ugakdj/)
- [r/gdpr: CMPs rely on periodic scans, new tags slip through](https://www.reddit.com/r/gdpr/comments/1wf2yv2/_/p9lyc7d/)
- [r/GoogleAnalytics: blocking triggers and traffic reporting](https://www.reddit.com/r/GoogleAnalytics/comments/1wmmz26/_/pb8ar52/)
