Skip to content
Skip to main content
Cloud Services Technical Explainer

Can several people use the same cloud account?

Yes. Several people may know the password, inherit a browser that is already signed in or use an application that still has access. But there is an important difference between sharing one account and several named users sharing the same files. The records produced by those two arrangements can be very different.

One account name can hide several routes in

Dave signs into Microsoft OneDrive through Edge on a shared Windows laptop. The same account is also active in the OneDrive phone app and in the Windows OneDrive sync client. If somebody else uses the remembered browser - or simply places a file inside the synchronised folder - the next cloud event may still carry Dave's account identity.

Now change the arrangement. Dave shares a SharePoint folder with Priya using her own work account. Priya reaches the same files, but through her own identity. The content is shared; the account is not.

Turn “it was shared” into something testable

Take one event - an upload, deletion, permission change or download - and build an access-route schedule around its exact time.

Possible route What would make it plausible? What should be compared next?
Dave entered the password A fresh interactive sign-in followed by the event Authentication method, application, IP address and Dave's device activity
Another person knew the password The same account but activity inconsistent with Dave Access opportunity, messages, browser profiles and the other person's device
A remembered browser was used An existing session with no matching fresh sign-in Browser profile, session continuity and physical access to that computer
OneDrive synchronised automatically A sync-client event rather than an interactive browser action Operation name, client information, local sync database and file timestamps
Priya used named access Priya's own account or sharing permission appears Recipient identity, permission history and Priya's corresponding device activity
The account was compromised Unfamiliar access accompanies recovery or security changes Sign-in pattern, alerts, consent grants, password changes and other sessions

This is the practical value of the card: possible sharing does not end attribution. It produces a finite set of routes that can be tested.

What named provider records may contribute

In Microsoft 365, Purview audit records may contain fields such as Operation, CreationTime, UserId, ObjectId, ClientIP, UserType and Workload. The precise fields depend on the service and event. Microsoft also separates interactive user sign-ins, non-interactive user sign-ins, service-principal sign-ins and managed-identity sign-ins in Microsoft Entra.

Google Workspace Drive log events can expose attributes including Actor, Event name, Document ID, App ID, App name, IP address and, where available, User device ID. Not every attribute appears for every event.

Those fields help distinguish routes, but the label “user” or “actor” still normally identifies the account context recorded by that system. It is not automatically the person at the keyboard.

Shared mailbox is not the same as a shared password

Microsoft says a Microsoft 365 shared mailbox is not intended for direct sign-in using its associated account. People normally access it through their own permitted accounts. That is an example of delegated access: several people use the shared resource while retaining separate entry routes.

If an organisation instead gives several people one ordinary username and password, the provider may have much less ability to distinguish them.

Record the conclusion at the right level

A useful conclusion might be:

OneDrive recorded the upload under Dave's account. The account was available through an Edge browser, a phone app and a Windows sync client. The next comparison is therefore between the event's client/session information and the corresponding activity on those devices.

That says what is established and names the next evidential bridge. It does not retreat to “anyone could have done it”, and it does not jump from the account name to Dave.

The point to remember

Shared access is a set of testable routes. Fix the event, list each realistic route into the account or content, and compare the provider record with the relevant person, application and device evidence.

Provider sources - checked 2 September 2026
Reference: CLD-010Cloud Services