Can cloud file metadata differ from device metadata?¶
Yes. Cloud and device metadata often describe different objects or stages of the same file journey. A difference is not automatically an error; it may show upload, download, synchronisation, conversion or later editing.
Compare fields by meaning, not label¶
A provider “created” time may date creation of the cloud object. A local “created” time may date arrival of a downloaded copy. An internal document date may pre-date both. Even identical labels can therefore refer to different events.
| Observation | Plausible explanation |
|---|---|
| Cloud object created Monday; local file created Thursday | File downloaded or synchronised on Thursday |
| Same content, different filenames | Rename in one system or independent export |
| Same filename, different hashes | Different versions or local edit |
| Cloud owner differs from embedded author | Administrative ownership and document metadata record different roles |
Time zones, device clocks and provider processing delay can create further apparent disagreement.
Preserve both sources¶
Do not overwrite one metadata set with the other. Record whether a value came from a provider export, audit log, live interface, sync database, filesystem or the file's internal properties. Note the object or version captured and the acquisition time.
Object IDs, version IDs, hashes, size, content and synchronisation records can establish how the copies relate. Where no reliable link exists, describe them as possible related items rather than assuming identity from the filename.
A difference can be positive evidence¶
Metadata may demonstrate that a copy arrived later, that cloud content changed while a device was offline, or that a local edit never synchronised. The mechanism explains the difference and determines what conclusion it supports.
OneDrive object OBJ-8821, version V-6, has service creation time 10:04 and hash H-A6. Dave's Surface receives budget.xlsx at 10:09 with the same hash and local created time 10:09. That match supports download or synchronised arrival after cloud creation. If Dave edits it offline and the local hash becomes H-B7 without a later provider version, the mismatch positively supports a device-side state not accepted by the service.
The next useful comparison is the provider version history against the device hash and filesystem times, sync database, queued or failed transfers and acquisition coverage.
Current Microsoft timestamp-source example - checked 3 September 2026
Microsoft Graph currently documents that driveItem dates are service-observed while fileSystemInfo dates are supplied for the local file. Microsoft warns that these values can differ; for example, a file created on a device on Monday may become a service object on Tuesday.
The point to remember
Cloud and device metadata belong to their own systems and events. Explain each field and the relationship between copies before treating a mismatch as inconsistency or manipulation.