Skip to content
Skip to main content
Cloud Services Technical Explainer

Could a file appear on a device without being created there?

Yes. A device can receive a file through cloud synchronisation, download, sharing, messaging, backup restoration or an application process. The local filesystem may say the item was “created” when it arrived, even though the content originated elsewhere.

Local creation time is not content origin

Filesystems need a time for the new local item. If a sync client downloads a document at 10:14, the local created time may be 10:14 even when the provider shows that the cloud object was uploaded two weeks earlier.

Dave's Surface Laptop illustrates the point. At 10:14 its OneDrive client creates local Projects\briefing.docx from provider object OBJ-7712, version V-8, which was accepted two weeks earlier. The device's creation record describes this local arrival; it does not move the document's cloud origin to 10:14.

Read local creation as one event in the route
EstablishedThe sync route can establish when this device obtained a representation of an earlier cloud object.
Still openWho authored the content and whether Dave knew of or used the arriving file.

Other processes can produce the same effect:

  • a shared folder is added to an account and downloads in the background;
  • a backup restores material to a replacement device;
  • a browser or application saves a file automatically;
  • a cloud app creates a preview, thumbnail or cached copy; or
  • another linked device uploads content that then propagates locally.

The local event describes arrival or generation of that representation. It does not necessarily describe authorship of the underlying content.

Trace the route into the device

The file's location often identifies the first useful question. A synced directory, browser-download folder, application cache and restored-backup path each imply a different mechanism and likely record source.

Where available, compare:

  • the provider object and version identifiers;
  • the local path and account mapped by the application;
  • sync-client transfer or database entries;
  • cloud upload and local creation times;
  • hashes or content features linking the copies; and
  • later open, edit, move or share activity on the device.

Synchronisation records can connect the originating cloud event to the receiving device more reliably than the filename alone.

Arrival, awareness and use are separate propositions

Automatic arrival can explain local possession without a manual download. It does not prove that the user knew about the file. Equally, automatic arrival does not prevent later evidence from showing awareness or use: a recent-file entry, application history, an edit, a manual move or content repeated in a message may provide that further link.

Established: the device held a local item linked to a particular cloud object or transfer.

Still open: where the content originated, whether the user knew it had arrived and what they later did with it.

Current OneDrive arrival example - checked 3 September 2026

Microsoft currently says that new files created online or on another device can appear as online-only items, while items inside a folder marked “Always keep on this device” download locally. Product icons and policy defaults can change. The provider-neutral principle is to distinguish the object's earlier history, the client's transfer and any later human interaction.

The point to remember

A local created time can mark the arrival of a copy, not the creation of its content. Use the folder, application and transfer records to reconstruct how the file reached the device.

Reference: CLD-056Cloud Services