Can one person use several cloud accounts?¶
Yes - and that is often entirely ordinary. The useful question is not “How many accounts does Dave have?” but “Which account was connected to the relevant event, and what reliably links that account to the others?”
Meet Dave's three cloud identities¶
Dave keeps personal documents in a Microsoft account, uses a Google Workspace account issued by his employer and has a separate Microsoft 365 administrator identity for occasional support work.
The names look similar, and all three accounts may appear on the same laptop. They are still separate provider identities with different owners, permissions, identifiers and records.
The cluster is a map of evidenced relationships. It is not permission to mix records from three accounts into one timeline without retaining their source.
The fictional addresses above use the reserved .example domain. They illustrate the structure; they are not real accounts.
Links have different strengths¶
Suppose a file moves from Dave's employer Google Drive to his personal OneDrive. That transfer connects two accounts to the same object and event sequence. It is usually more informative than discovering that both accounts once used the office internet connection.
| Connection | What it can contribute | What remains open |
|---|---|---|
| Same device profile | Both accounts were configured in one browser or application environment | Who used that profile for each event |
| Same recovery number | One telephone route was associated with both accounts | Whether Dave controlled it at the relevant time |
| Direct file share or transfer | The accounts interacted around a particular object and time | Why the transfer occurred and who initiated it |
| Same payment instrument | One customer relationship funded both services | Whether another authorised person used the accounts |
| Repeated paired sign-ins | The accounts appear in a consistent time/device pattern | Whether the pattern is unique to one user |
| Same display name | The labels resemble one another | Very little without a stronger identifier |
Several independent, time-relevant links can support an account cluster. One weak reused identifier should not quietly become proof that every event belongs to Dave.
What the provider may call the account
Provider terminology is not interchangeable.
- A personal Microsoft account is distinct from an organisation-managed Microsoft 365 or Microsoft Entra identity.
- A Google Workspace account sits within an organisation's administrative environment; the organisation may control the account and relevant logs.
- An administrator identity should be recorded with its role and relevant period because it may have powers that Dave's ordinary work account did not.
Capture the provider's stable internal identifiers where available, not only the visible email address or display name. Names can change, aliases can exist and the same-looking address may appear in different contexts.
A Google Workspace detail that can change the search
Google states that Drive log events record the actor's primary email address even where an alias is involved. Its current documentation also warns that, after a user is renamed, searching under the old name does not return the renamed user's events.
That is a concrete reason to preserve the identifiers and names shown in the original return, record the relevant period and ask whether the account was renamed.
Produce a map another person can audit¶
For every proposed cluster, record:
- the exact provider and account identifier;
- who controlled the tenant or customer relationship;
- the account's role and relevant dates;
- the event that matters;
- every proposed connection to another account;
- the source supporting each connection; and
- the alternative explanation still requiring a test.
This prevents a common analytical error: finding one persuasive link and then silently treating all activity across every account as one person's activity.
Where an account belongs to an organisation, distinguish the tenant, individual profile and administrator role. Personal and organisational accounts create different evidence-holder and control questions.
The point to remember
Link accounts; do not merge them. A defensible account cluster preserves every identity and event separately, then shows the specific records that connect them.