What happens when a cloud file is deleted?¶
Deletion usually removes the object from the live user view and starts a service-defined lifecycle. Content, versions and records may continue in deleted items, retention systems, backups or other users' and devices' copies.
Deletion has stages¶
A service may first mark the object deleted or move it into a recycle bin. It may later expire or purge the content while retaining an audit event. Organisational retention or legal-hold controls can preserve data beyond what the ordinary user can see.
The deletion may also revoke sharing, propagate to synced devices and create new object, version or audit records. Restoration can create another recorded event.
Identify the actor and mechanism¶
Provider logs may associate deletion with an account, session, application or administrator. It might equally result from a retention policy, automated workflow or change synchronised from another device.
Preserve the object and version IDs, deletion time, event ID, actor/process, original location, deleted-item state and applicable retention setting. These distinguish user deletion from policy expiry and show what the service retained.
“Deleted” describes availability, not universal destruction¶
Other users may have downloaded or copied the file. Offline devices, backups and earlier versions may survive. Deletion across devices depends on synchronisation state.
Priya deletes OneDrive object OBJ-4407, version V-19, from SharePoint folder /Briefings at 15:04. Audit event DEL-204 records her account C-66308 and session SES-55A1; the service moves the object into deleted-item state BIN-31, while retention rule RET-7 preserves a compliance copy HOLD-88. The event establishes removal from the live folder and the recorded route, not destruction of every copy.
The next useful comparison is DEL-204 against session SES-55A1, deleted-item metadata, retention rule RET-7, restore or purge events, connected-device sync and known recipient copies.
Current Microsoft deletion-lifecycle example - checked 3 September 2026
Microsoft currently describes a OneDrive or SharePoint recycle-bin stage and separate retention behaviour. For retained SharePoint or OneDrive content, deletion can cause a copy to be stored in the Preservation Hold library. Exact recovery periods and paths depend on account type, tenant settings, holds and policy.
The point to remember
Cloud deletion begins a provider-defined lifecycle. Establish the mechanism and retention state before concluding what disappeared, what remains and who caused the change.