Skip to content
Skip to main content
Cloud Services Technical Explainer

Can the same cloud account have several active sessions?

Yes. One account may simultaneously have browser, phone, desktop, sync-client and connected-application sessions, each with its own identifier, lifecycle and authority. Evidence about one session should not silently be applied to all of them.

Activity can occur in parallel

At 15:00, Dave's Microsoft 365 account has three routes: Edge on his laptop under session SES-L41; Outlook on his phone under SES-P09; and a connected backup application using delegated authority APP-77. OneDrive records a large download under SES-P09 while Dave continues editing a document through SES-L41.

Sessions may have different creation times, authentication methods, clients, devices and connection addresses. Some are interactive; others synchronise or refresh in the background.

In compromise, the legitimate user may continue normal work while an intruder uses another session. Continued genuine activity does not disprove unauthorised access, and the latest login need not be responsible for every later event.

Reconstruct historical sessions

Current session lists exclude routes that expired or were revoked. Use session identifiers, authentication, token and audit records to map which sessions were active and what each did. Preserve per-route creation, last-seen and revocation records rather than relying on a current-session screenshot alone.

Closing one browser, resetting one device or revoking one session may leave others active. Response records should state the scope of any containment action.

Attribute per event

Associate each important action with its session and client before connecting it to a device and person. The next useful comparison is the login and resource event for each session, followed by local browser, phone or application evidence. Treating the account as one continuous user obscures parallel access.

The point to remember

An account can support several simultaneous access routes. Reconstruct each session and attribute its events separately, especially where legitimate and unauthorised activity overlap.

Reference: CLD-108Cloud Services