Skip to content
Skip to main content
Cloud Services Technical Explainer

How long might a cloud provider retain records?

There is no reliable universal duration. The answer may range from a short operational window to long-term retention, depending on the exact record, product, configuration and historical account state.

Define the evidence before asking for a period

Login events, active sessions, file audit history, deleted content, backups, billing and support records are different datasets. “Cloud logs” is not precise enough to determine availability.

Record the provider and product, personal or organisational account, subscription or licence, tenant settings, region where relevant, record type and event date. Account closure, downgrade or disabled logging may change the position.

Published periods need historical context

A current help page may not describe the plan or configuration that applied during the event. Preserve the source and date of any retention statement, and confirm whether it describes visibility, export, preservation or actual provider-held availability.

Retention does not guarantee completeness. A dataset may have been enabled late, filtered, sampled or unavailable for particular event types.

Availability is the decisive answer

Where loss risk is real, establish whether the specific records exist now and consider targeted preservation. Secondary sources - customer exports, security alerts or connected applications - may outlast the provider view.

An investigator asks for Dave's “Microsoft cloud logs” from 1 June. That phrase is split into Entra sign-ins, Purview audit events, SharePoint versions and deleted content. Policy export POL-2026-06-01 shows audit rule AUD-04 and content rule RET-17; a query on 3 September returns event EVT-9041 from Purview but the interactive sign-in view no longer contains its earlier authentication record. This establishes present availability for the audit event and a defined gap in that sign-in source - not that no authentication occurred.

Replace a generic period with a dated availability test
EstablishedThe dated query establishes which defined audit record remains available from that source now.
Still openWhy the sign-in record is absent and whether another provider or customer system retained it.

The next useful comparison is EVT-9041 against the historical policy export, exact Purview query, Entra export or API return, connector archives and any contemporaneous security alert.

Current Microsoft record-duration example - checked 3 September 2026

Microsoft publishes separate retention controls for audit records and content, with availability affected by licensing, policy priority and configuration. Current documentation must be dated and tested against the historical tenant and the actual return.

The point to remember

Do not quote a generic retention period. Define the exact record and historical service state, then verify present availability and preserve the source of that answer.

Reference: CLD-093Cloud Services