Skip to content
Skip to main content
Cloud Services Technical Explainer

Could another linked device change the cloud record?

Yes. Any device or client with continuing authority to the account may upload, edit, move, rename or delete cloud objects. The device being examined is only one possible source of the provider event.

Provider records may contain a session, client or installation ID, application, browser details, public IP address and token information. These can distinguish routes even when several devices use the same account.

Current trusted-device lists are not complete history. Devices can be removed, reset or renamed, and a browser session may not appear as a neatly identified physical device. Historical authentication and session records may preserve an earlier route.

Synchronisation can delay the visible event

A laptop may edit a file while offline and upload the change hours later. The provider timestamp then dates receipt, while local application and sync logs date the earlier edit. Another device can also generate a deletion that subsequently propagates to the device in front of the investigator.

Compare the cloud object and version event with device-specific sync databases, client IDs, local paths and application activity. A matching IP address helps identify a connection but is not a unique physical-device identifier.

Dave edits route-plan.docx on laptop DEV-A7 while offline at 09:18. OneDrive sync client OD-77 later submits version V-20 of object OBJ-3108 at 11:26. The Surface being examined, DEV-B4, receives that version at 11:29. The provider event establishes the OD-77 route; the laptop sync database and local save establish the earlier source, while the Surface records establish receipt rather than creation.

Keep device association and user attribution separate

Separate the source device from the device that later receives the change
EstablishedThe joined records distinguish the originating client route from the later receiving device.
Still openWho controlled the source laptop and whether its local save was interactive or automated.

The next useful comparison is OD-77 and V-20 against each device's sync database, local application save, session history, network connection and content hash.

Current Microsoft client-route example - checked 3 September 2026

Microsoft Purview audit records can expose operation, object, user, client and correlation properties, while Microsoft Entra sign-in records distinguish interactive, non-interactive and service-principal routes. Exact fields and availability depend on workload, licensing and logging configuration.

The point to remember

Do not assign every cloud event to the available device. Identify the provider's client route and corroborate it with historical session and device records.

Reference: CLD-080Cloud Services