Does a cloud timestamp show when the user acted?¶
Not necessarily. A cloud timestamp dates an event or state recorded by the service. It may be close to a person's action, or it may date later synchronisation, processing or automation.
Identify the event behind the time¶
“14:22” is incomplete without the field definition. It could be an authentication, object creation, upload, version save, access, conversion or audit-ingestion time. Some fields describe when the provider received an event; others preserve a time supplied by a device or file.
An offline edit illustrates the difference:
| Time | Source | Event |
|---|---|---|
| 09:18 | Laptop | Document edited and saved while offline |
| 11:26 | Provider | Updated version received during synchronisation |
| 11:27 | Audit system | Version event written to searchable log |
The provider record is accurate for receipt. It does not date the original editing action.
Check the clock and precision¶
Record the time zone or UTC offset, seconds or finer precision, source clock and whether the interface has converted the display to local time. Batching, queueing and clock error can affect ordering where events are close together.
Build the human timeline across sources¶
Authentication and session records may place an account in use. Device and application records may date the local action. Version, sync and audit entries explain when the cloud learned about it. Together they can support a narrow time range more reliably than one field.
Dave saves route-plan.docx on his offline Surface at 09:18. OneDrive client OD-77 reconnects and submits object OBJ-3108 at 11:26; Microsoft Purview makes audit event AUD-901 searchable at 11:27. The three timestamps can all be accurate because they date local save, provider receipt and audit ingestion. Joined with session and device records, they support a bounded sequence rather than the false claim that Dave edited at 11:26.
The next useful comparison is the timestamp field definition and time zone against the local application save, sync queue, provider operation, audit ingestion and account session.
Current Microsoft service/client time example - checked 3 September 2026
Microsoft Graph currently distinguishes service-observed drive item dates from client-supplied fileSystemInfo dates. Microsoft Purview audit records add their own event and processing fields. Preserve the raw values and field definitions before converting them into one display time.
The point to remember
A cloud timestamp dates the event defined by its source. Establish that event, clock and processing path before using it as the time a person acted.