What is the difference between a cloud file and a local file?¶
A cloud file is an object managed by a provider; a local file is an item held in a device's filesystem. They may contain identical data and appear under the same name, but each has its own location, identifiers and history.
The two records answer different questions¶
| Question | Cloud source may answer | Device source may answer |
|---|---|---|
| What is the item? | Object, folder and version IDs | Path, filename, size and filesystem identity |
| When did it change? | Upload, server modification and version events | Local creation, write and access times |
| Who or what handled it? | Account, session, application and permission | Logged-in profile, process, app and device activity |
| Is the content present? | Current or retained provider content | Full file, offline copy, cache, preview or placeholder |
The provider can record an account action without identifying the human user. The device can show local presence without proving that the user created or knowingly opened the content.
One cloud object can have several local representations¶
Dave's OneDrive records object OBJ-4407, version V-12. His Surface Laptop holds a full synchronised copy, his phone holds a thumbnail, and another Windows device lists an online-only placeholder that retrieves the content when opened. All three refer to the same provider object, but only the Surface currently stores the full content.
The reverse also occurs. A downloaded copy can be moved outside the synced folder and edited independently. It may keep the same filename while no longer representing the current cloud version.
Timestamps describe events in their own system¶
A local “created” time may record when synchronisation placed a copy on that device. A cloud “modified” time may record a server-side save. Exporting, restoring or copying the file can create further timestamps without changing when the original content was authored.
This is why cloud and device data should be compared through object IDs, version IDs, hashes, sync records and the event timeline rather than through filenames or one timestamp alone.
State the relationship, not an assumption¶
Useful conclusions distinguish the two sources:
- “The provider retained version
V-12under accountC-54119.” - “The laptop held a full local copy linked to
OBJ-4407.” - “The phone displayed a cached preview; a full local copy was not established.”
None of those statements alone establishes authorship or conscious use.
Current OneDrive local-state example - checked 3 September 2026
OneDrive Files On-Demand currently distinguishes online-only, locally available and always-available files. Microsoft states that opening an online-only file downloads it and makes it locally available; marking it “Always keep on this device” retains a local copy for offline access. These interface labels can change. The durable question is whether full content, only a reference/preview, or an independent copy was present at the relevant time.
The point to remember
Cloud and local files may be related versions or independent copies. Identify what each system actually held and recorded before treating them as the same evidential item.