Skip to content
Skip to main content
Cloud Services Technical Explainer

Does an account name prove who created the file?

No. It identifies the cloud identity displayed or recorded against an event. The file may have been uploaded, synchronised, generated by software or created through a session controlled by somebody else.

Prefer the internal identity to the label

Display names can change, be duplicated or show the current value beside historical activity. Preserve the internal user ID and tenant or workspace context, plus any historical email or account identifiers at the event time.

Establish what “created” means

The account may have created a new provider object while uploading content authored elsewhere. A linked device may upload automatically, an application may generate the file, or ownership may later transfer. Creation of the cloud object, authorship of content and current ownership are separate events.

Useful records include the creation or upload event, session, application/client ID, source device, object/version IDs and subsequent revision history. These explain why the account name appears.

Device activity, authentication, communications and work context may connect the recorded account and session to a person. Shared or compromised access is a specific alternative to test, not a reason to discard a strong converging evidence chain.

Dave's account C-77503 is shown beside the creation of OneDrive object OBJ-6120, report.docx, at 09:10. Audit event UP-330 shows Android client OD-A17 uploaded the file; its embedded author property says “Priya”, and the local photograph-to-document workflow began earlier on device DEV-P9. The account label reliably identifies the provider identity used for upload, not who authored the document content.

Ask what the account name labels in this specific event
EstablishedThe provider associated account C-77503 and Android client OD-A17 with creation of the cloud object.
Still openWho supplied the content, controlled the client and authorised or knew of the upload.

The next useful comparison is UP-330 against the account session, client/device identifiers, local source file and hash, embedded-property history and communications transmitting the content.

Current Microsoft identity-field example - checked 3 September 2026

Microsoft Graph drive and version resources expose stable service identifiers and recorded identities. Their fields describe the provider object or version; they do not by themselves resolve who controlled an account or authored imported content.

The point to remember

An account name identifies a cloud identity, not the human creator. Preserve the internal ID and creation route, then use session, device and contextual evidence for personal attribution.

Reference: CLD-083Cloud Services