Does access to a shared link identify the person who used it?¶
Not by itself. A shared-link event may identify a signed-in account, an application or only a network connection. Personal attribution requires a bridge from that recorded actor to the person using it at the relevant time.
Authentication determines the starting point¶
For a named-user link, the provider may record an account, session, device or application identifier. That is stronger than an anonymous event because it narrows the access route, but a shared, delegated or compromised account remains possible.
For an unrestricted link, the service may record only:
- the share and target object IDs;
- timestamp and action such as preview or download;
- public IP address;
- browser or client information; and
- referrer or coarse location, where retained.
An IP address identifies a connection, not a person. The route may involve shared Wi-Fi, a mobile network, workplace gateway, VPN or other intermediary.
Some events are not human use¶
Messaging platforms may generate a preview when the link is pasted. Email and security systems may scan it. Search, archiving or compliance tools may fetch content automatically. Close timing to delivery is useful context, but it should not turn an automated request into a human view.
Provider event labels and client identifiers can help distinguish these mechanisms. Repeated access, a completed download, later editing or a signed-in session may add weight, depending on the service.
At 10:32 OneDrive records FileDownloaded for share SH-8F21, object OBJ-4407, from 198.51.100.24 using client Edge 140. Dave's Surface browser history records the same share URL and a completed budget.xlsx download at 10:32, while his Microsoft 365 session is active on that device. Those joined records are much more informative than the connection address alone.
Build the personal bridge from independent records¶
Communications can show who received or forwarded the link. Device evidence may show the message, browser session, downloaded file or application activity. Account-session records and surrounding conduct may place the access with a particular user.
The next useful comparison is the provider event against the precise account session, browser or download records and surrounding communications, while testing scanners, preview generators and other authorised users.
Current Microsoft audit-event example - checked 3 September 2026
Microsoft Purview currently documents file and sharing audit operations with properties such as the affected object, user or application, client IP address, operation, result and workload-specific identifiers. Available detail varies by event and licensing. Preserve the supplied audit schema and event values rather than treating a display label as a complete attribution record.
The point to remember
A shared-link event identifies the route used at the level the provider recorded. Attribute the person only when account, device, communications and contextual evidence complete the connection.