What is cloud persistence?¶
Cloud persistence is continuing or renewed access through an authority that remains after the original entry route is closed. The relevant evidence is a lifecycle - who created the route, what it could reach, when it was used and what finally ended it - not the feature name alone.
One entry session can create several later routes¶
In this fictional example, an unauthorised session associated with Dave's account creates guest G-204, grants application APP-73A1 file permission and creates sharing link L-551. Dave's password is later reset, but each new route has its own authority and audit history.
A legitimate feature becomes persistence through context¶
Guests, applications, service identities, recovery methods, sharing links and forwarding rules have ordinary uses. Suspicion comes from their relationship to the event: an unexplained creator, unusual timing, excessive scope, deceptive name, first use after containment or activity inconsistent with the approved purpose.
Maintain an authority schedule containing the route type and stable ID, creator account/session, permission or scope, creation, first/last use, target resources, owner or approver, and expiry/revocation/removal. Compare it with identity, application, resource, device and change-management records. That schedule distinguishes a single compromised login from an effort to retain access.
Access surviving a password reset supplies the cut-off test. Evidence of account takeover shows how the entry, continuing authority and resulting activity combine into a wider conclusion.
Current Microsoft Entra example - checked 2 September 2026
Microsoft currently advises monitoring Add user, role-assignment and authentication-method changes as possible continued-access routes. Its malicious-application investigation guidance also describes an already compromised administrator creating an OAuth application for longer-term access and recommends examining application owners, consent administrators and grant activity.
Provider controls and audit coverage differ. The durable method is to identify every authority and preserve its lifecycle rather than copy one vendor's persistence checklist.
The point to remember
Cloud persistence is a continuing-authority relationship. Map each route from creator to use and termination, then test its purpose and control separately.