Skip to content
Skip to main content
Cloud Services Technical Explainer

What evidence might identify the session that changed a file?

The strongest route is a stable identifier connecting the file event to session, authentication and client records. Where no session ID is retained, a careful correlation of account, time, application, device and network fields may narrow the route.

Start with the object event

Preserve the object and version IDs, exact timestamp and time zone, event or request ID, recorded account, application and action. Correlation or request IDs can join records across provider logging systems more reliably than approximate timing.

The session may have been created long before the change. A remembered browser, refresh token or sync client can act without a fresh login immediately beforehand.

Follow the relationship across logs

Authentication records may show session creation and MFA. Session or token records may show lifecycle and client details. File audit logs show the object action. Device evidence may contain the same client ID, local path or sync event.

Example join: file event EVT-9041 → session SES-41C2 → client DEV-A7 → sign-in AUTH-1882.

If the provider exposes only an IP address and browser string, state the weaker correlation and test other sessions that share those features.

For example, OneDrive file event EVT-9041 records object OBJ-4407, version V-19, session SES-41C2 and client OD-77 at 14:22. Entra sign-in AUTH-1882 created that session on Surface DEV-A7 at 13:58. The stable session relationship is stronger than matching time and IP alone, but it still attributes a technical route rather than a person.

Session is not person

An identified session can be shared, stolen or active on a compromised device. Personal attribution requires evidence of who controlled that device or client and whether an application performed the event.

Join the file event to its session before testing the person
EstablishedStable identifiers join the file change to a particular session, client and authenticated device record.
Still openWhether Dave controlled that device and whether a person or authorised process caused the action.

The next useful comparison is SES-41C2 across token lifecycle, authentication, device registration, OneDrive client logs and local application activity, including other sessions sharing the account or network.

Current Microsoft session-correlation example - checked 3 September 2026

Microsoft Purview audit properties can include operation, object, user, client and correlation identifiers. Microsoft Graph activity logs can record requests received for a tenant and support correlation with sign-in information when the required diagnostics are enabled.

The point to remember

Join the file event to session and authentication records using stable identifiers where possible, then corroborate the device and user separately.

Reference: CLD-082Cloud Services