Does an account name prove who created the file?¶
No. It identifies the cloud identity displayed or recorded against an event. The file may have been uploaded, synchronised, generated by software or created through a session controlled by somebody else.
Prefer the internal identity to the label¶
Display names can change, be duplicated or show the current value beside historical activity. Preserve the internal user ID and tenant or workspace context, plus any historical email or account identifiers at the event time.
Establish what “created” means¶
The account may have created a new provider object while uploading content authored elsewhere. A linked device may upload automatically, an application may generate the file, or ownership may later transfer. Creation of the cloud object, authorship of content and current ownership are separate events.
Useful records include the creation or upload event, session, application/client ID, source device, object/version IDs and subsequent revision history. These explain why the account name appears.
Build the human link¶
Device activity, authentication, communications and work context may connect the recorded account and session to a person. Shared or compromised access is a specific alternative to test, not a reason to discard a strong converging evidence chain.
Dave's account C-77503 is shown beside the creation of OneDrive object OBJ-6120, report.docx, at 09:10. Audit event UP-330 shows Android client OD-A17 uploaded the file; its embedded author property says “Priya”, and the local photograph-to-document workflow began earlier on device DEV-P9. The account label reliably identifies the provider identity used for upload, not who authored the document content.
C-77503 and Android client OD-A17 with creation of the cloud object.The next useful comparison is UP-330 against the account session, client/device identifiers, local source file and hash, embedded-property history and communications transmitting the content.
Current Microsoft identity-field example - checked 3 September 2026
Microsoft Graph drive and version resources expose stable service identifiers and recorded identities. Their fields describe the provider object or version; they do not by themselves resolve who controlled an account or authored imported content.
The point to remember
An account name identifies a cloud identity, not the human creator. Preserve the internal ID and creation route, then use session, device and contextual evidence for personal attribution.