What is cloud authentication?¶
Cloud authentication is the service deciding whether presented credentials, factors or trusted identity information satisfy its rules for an account, device or application. A successful result establishes accepted access in an identity context; it does not by itself identify the human at the keyboard.
Dave opens OneDrive once and works for hours¶
At 08:42 Dave opens OneDrive in Microsoft Edge on a Windows laptop. Microsoft Entra accepts his account and required authentication methods. The service then issues access that the browser can use for later requests. At 11:06 Dave opens route-sheet.xlsx without typing his password again.
The 08:42 sign-in and 11:06 file access are related but different events. Authentication establishes the access route. The later OneDrive record describes use through the resulting session or token.
Authentication is a provider decision at a point in time. A session or token can separate that decision from later cloud activity.
Read the sign-in as who, how and what¶
| Question | Example field or value | Investigative meaning |
|---|---|---|
| Who? | User ID 4a86…91bd; username dave@northstar.example | The directory identity presented for the attempt |
| How? | Client app Browser; authentication methods and result | The access route and checks the provider recorded |
| What? | Application Microsoft Office 365; resource ID | The service or resource for which access was sought |
| When/from where? | 2026-07-10T08:42:13Z; IP address; browser and operating system | Time and technical context to compare with other records |
| Which transaction? | Correlation ID and request ID | Keys that may connect related sign-in or token activity |
Preserve the provider's exact event type. An interactive user sign-in is not the same as a non-interactive sign-in, managed identity or service-principal event. Background activity may represent an application renewing or using existing authority rather than a person entering credentials again.
Authentication can use several routes¶
The presented material might be a password, a multi-factor authentication method, a device-bound credential, a certificate, an assertion from an identity provider or an application secret. The provider may also evaluate policy and risk signals before granting access.
That means “correct password” is often an inadequate summary. Record the authentication requirement, method sequence, result, application, resource and whether the event was interactive. If the service accepted a previous claim rather than presenting a fresh prompt, that distinction changes how the event should be described.
How Microsoft Entra currently presents sign-in evidence - checked 2 September 2026
Microsoft describes each Entra sign-in around Who (identity), How (client/application) and What (target resource). The details can include user and application identifiers, authentication requirement, IP address, browser/operating system, correlation ID, request ID and authentication-method steps.
Microsoft also distinguishes interactive user, non-interactive user, service-principal and managed-identity sign-ins. Its documentation warns that authentication details can be aggregated after the initial event and that a requirement may have been satisfied by a claim obtained earlier.
Connect the decision to what happened next¶
Compare the authentication event with the cloud session, access token, device/browser record and resource activity. Matching stable user, application, resource, time and correlation values can support a strong technical chain. Device possession, communications and evidence of shared or compromised access address the separate personal-attribution question.
The point to remember
Authentication records the service accepting an identity route. Preserve the provider's who, how, what and transaction fields, then follow the access into the session and resource event.