What is cloud storage?¶
Cloud storage is a provider-managed service that keeps data as online objects and controls how accounts, applications and links can reach them. It is more than a remote disk: the service may maintain identifiers, versions, permissions, deleted items and audit events alongside the visible file.
The familiar folder is a service view¶
A browser, phone app or desktop folder presents the files in a familiar way, but the provider performs the underlying work. It authenticates an account, resolves a folder and object, checks permission, then returns content or records a change.
One object can therefore have several related elements:
- a provider object ID that can remain stable when the filename changes;
- current content and earlier versions;
- an owning account or workspace;
- permissions for other accounts, groups or shared links;
- server-side created, uploaded and modified times; and
- events for access, editing, download, sharing or deletion where the service records them.
What cloud storage can show brings these elements together as an investigator-facing evidence model.
Cloud storage can create several evidence locations¶
The provider may hold the authoritative object and service history. A customer organisation may hold separate identity, security or audit records. Connected devices may contain full copies, offline copies, cached previews, placeholders and synchronisation databases. Other users may possess copies obtained through sharing.
These sources are related but not interchangeable. A provider event can associate an action with an account or session. A local artefact may show that content reached a particular device. Further evidence is needed to establish the person who controlled either of them.
How a simple upload becomes a cloud record¶
Dave saves handover.docx inside the OneDrive folder on his Surface Laptop. The OneDrive client detects the local change, submits it through Dave's account context and the service creates object OBJ-4407, version V-12. The service then evaluates who can reach that object and makes the accepted state available to other authorised clients.
The visible result is one filename. The evidential result may include a local filesystem history, sync-client entry, account session, provider object, version and access trail.
Describe the service and object precisely¶
“Found in the cloud” leaves the important relationships unstated. Record the service, account or tenant, folder, object and version identifiers, and whether the material came from a provider export, live account view or device examination.
Current OneDrive object example - checked 3 September 2026
Microsoft Graph currently represents a OneDrive file or folder as a driveItem, and represents a particular retained state as a driveItemVersion with its own version ID, modification time, modifier identity and size. Product interfaces and export schemas can change; preserve the values in the supplied return rather than assuming the visible name is the stable identity.
The point to remember
Cloud storage manages objects and their access history, not just remote copies. Read the provider, account, object, version and device records together before attributing creation, possession or use.