Who controlled the account?¶
Account control is about who had the practical ability to get in, recover it, secure it, delegate access or lock somebody else out.
That can be more useful than the registered name, especially where the account has been shared or compromised.
Look for control events¶
Useful provider records may include:
- password changes;
- recovery-email or telephone changes;
- multi-factor enrolment;
- trusted-device decisions;
- session revocation;
- new application consent;
- permission changes; and
- account-recovery events.
These events can show how control shifted over time.
That sequence may be far more informative than the current settings page.
Control can change¶
An account might be:
- controlled normally by its legitimate holder;
- taken over by somebody else;
- recovered by the legitimate holder later.
If you only inspect today's settings, you may miss the period that actually matters.
Build the control picture around the relevant time, not the present day.
Knowing a password is not always full control¶
Somebody may know the password but not control the recovery email or multi-factor method.
Another person may control recovery and be able to reset the password and eject every session.
An organisational administrator may be able to suspend or reset an account without producing its everyday content.
So ask what practical authority the person actually had.
Control and use are different¶
A person may control an account but let somebody else use it.
A business owner may control recovery while employees operate the account day to day.
A compromised account may be controlled by an offender for a short period while still being registered to the victim.
Who was actually using the account? takes that last step.
The practical point is: reconstruct account control as a timeline of security and recovery authority. Then deal separately with who performed the event you care about.