Skip to content
CLD-108 Cloud Services

Cloud ServicesCLD-108

Can the same cloud account have several active sessions?

Yes. The same cloud account can have several active sessions at the same time.

A user may be signed in on a phone, laptop, tablet, browser and connected application.

What this means in practice

Each session may have a different creation time, device, IP address, application and authentication method.

Some sessions may be interactive. Others may operate in the background through mobile applications, sync clients or delegated services.

An attacker may also use one session while the legitimate user continues using another.

Investigators should identify all active and historical sessions around the relevant period.

Likewise, closing one browser or resetting one device may leave other sessions active.

If the account must be secured, session revocation may need to be applied broadly and coordinated with evidence preservation.

What this does not show on its own

The dangerous assumption is that all activity under one account came from one device or one continuous user action.

Where compromise is suspected, continued legitimate activity does not rule out parallel unauthorised access.

Current session lists may not show sessions that have expired or been revoked. Historical login and audit records may therefore be needed to reconstruct the sessions active at the time of the event.

What to do next

Compare session IDs, devices, browsers, applications, IP addresses, token activity and later actions.

Do not assume that the most recent login created the session responsible for every event. An older session may remain valid and continue operating.

Key takeaway

One cloud account may support several simultaneous sessions, so attribute each event to the relevant session and device rather than treating the account as one continuous connection.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.