Skip to content
Skip to main content
Cloud Services Technical Explainer

Which cloud records are most volatile?

Yes. Detailed sessions, connection data, security alerts, deleted items and audit events may have short or configurable availability. Records visible now may expire before a slower acquisition route completes.

Volatility is record-specific

Account type, licence, tenant settings, logging configuration and product changes can all affect retention. Downgrade, account closure or disabled logging may shorten or end access.

Identify the exact provider, tenant or account, record type, event period and identifiers. A vague concern about “cloud logs” is not enough to preserve or request the right dataset.

Other systems may hold copies

Customer security platforms, alert emails, local administrator exports and connected applications may receive records before provider expiry. Those copies may become the only surviving source, although their fields and provenance should be preserved.

Provider backups should not be assumed to contain searchable event logs. Backup and operational-log systems have different purposes.

Absence after expiry is not absence of event

Document the retention position and any delay affecting availability. A missing expired record cannot prove the event did not occur; other evidence may still reconstruct it.

At 09:20 on 1 June, Entra sign-in AUTH-1882 contributes to OneDrive file event EVT-9041. When Priya checks the interactive sign-in view on 3 September, that source returns no matching row, but a Sentinel export ingested at 09:21 retains correlation ID CORR-77, account C-77503, public IP address and outcome. The exported record can establish that the earlier authentication event was observed and copied. It does not make the later provider view complete or prove that every original field was exported.

Preserve a volatile record through an identifiable secondary route
EstablishedThe sourced export establishes that the authentication event was observed and retained outside the later view.
Still openWhy the provider row is absent and which original fields or neighbouring events were not exported.

The next useful comparison is CORR-77 across the Sentinel raw event, connector configuration and health, Purview EVT-9041, any Entra API export and the provider's dated retention policy.

Current Microsoft volatile-record example - checked 3 September 2026

Microsoft audit and identity records have source-specific retention and licensing controls. Audit-log retention policies can prioritise selected users and record types, while an exported security platform copy follows its own ingestion and retention configuration.

The point to remember

Treat volatile cloud records as precise datasets with an expiry risk. Identify and preserve them early, including secondary copies held by the customer or security systems.

Reference: CLD-097Cloud Services