Can the same cloud account have several active sessions?¶
Yes. One account may simultaneously have browser, phone, desktop, sync-client and connected-application sessions, each with its own identifier, lifecycle and authority. Evidence about one session should not silently be applied to all of them.
Activity can occur in parallel¶
At 15:00, Dave's Microsoft 365 account has three routes: Edge on his laptop under session SES-L41; Outlook on his phone under SES-P09; and a connected backup application using delegated authority APP-77. OneDrive records a large download under SES-P09 while Dave continues editing a document through SES-L41.
Sessions may have different creation times, authentication methods, clients, devices and connection addresses. Some are interactive; others synchronise or refresh in the background.
In compromise, the legitimate user may continue normal work while an intruder uses another session. Continued genuine activity does not disprove unauthorised access, and the latest login need not be responsible for every later event.
Reconstruct historical sessions¶
Current session lists exclude routes that expired or were revoked. Use session identifiers, authentication, token and audit records to map which sessions were active and what each did. Preserve per-route creation, last-seen and revocation records rather than relying on a current-session screenshot alone.
Closing one browser, resetting one device or revoking one session may leave others active. Response records should state the scope of any containment action.
Attribute per event¶
Associate each important action with its session and client before connecting it to a device and person. The next useful comparison is the login and resource event for each session, followed by local browser, phone or application evidence. Treating the account as one continuous user obscures parallel access.
The point to remember
An account can support several simultaneous access routes. Reconstruct each session and attribute its events separately, especially where legitimate and unauthorised activity overlap.