Skip to content
Skip to main content
Cloud Services Technical Explainer

What is cloud-provider retention?

Cloud-provider retention is the set of rules and technical periods governing how long each kind of customer data or service record remains available. It is not one expiry date for an entire account.

Different records follow different schedules

Live content, deleted items, versions, authentication events, audit logs, security alerts, billing and backups may each have separate retention. Availability can also depend on product, subscription, tenant configuration, region and account status.

The ordinary interface may stop showing data before provider, administrator or compliance systems remove it. Conversely, a provider may keep billing information while detailed activity logs have expired.

Retention has several owners

The provider sets platform limits and defaults. A customer organisation may configure shorter or longer periods, export logs to a security platform or operate separate archives and backups. Identify which system is the likely record holder.

Ask about the precise record

“Does the provider keep data?” is too broad. Specify the service, account or tenant, record type, event period and relevant identifiers. Preserve the retention information and date it was confirmed because products and policies change.

Retention duration remains an evidence-specific question, not a familiar-provider assumption.

Dave's organisation uses Microsoft 365. Purview policy RET-17 covers SharePoint site SITE-21, while audit policy AUD-04 covers selected user activity and a separate Sentinel workspace receives exported sign-in records. When object OBJ-4407 is deleted, a compliance copy may remain even though the user view changes; the audit and exported sign-in records follow different clocks. The policy records establish which systems were configured to retain which classes of evidence, not that every expected event was successfully recorded.

Map retention by record class and controlling system
EstablishedThe configuration establishes distinct retention routes for content, audit and exported authentication records.
Still openWhether each system captured the particular event completely and still holds it now.

The next useful comparison is RET-17 and AUD-04 policy history against OBJ-4407, the relevant event date, the Sentinel connector health and actual returns from all three systems.

Current Microsoft retention model - checked 3 September 2026

Microsoft Purview separates retention policies and labels for content from audit-log retention policies. Scope, licensing and configuration can differ, and exported records then follow the destination system's own policy.

The point to remember

Cloud retention varies by record, product and configuration. Identify the exact evidence source and its current availability rather than applying one period to the whole service.

Reference: CLD-092Cloud Services