Skip to content
Skip to main content
Cloud Services Operational Explainer

What should I record about a cloud login event?

Preserve enough raw detail to identify the account, event, authentication route, connection, client and resulting session. A screenshot or location label alone rarely retains the full evidential record.

Core event fields

Record the provider and service, tenant and account IDs, event ID, exact time and time zone, event type and outcome. Add the authentication and MFA method, identity provider, session/token or correlation IDs, application/client, full IP address, raw user agent or device ID, risk indicators and failure code where present.

Distinguish a fresh sign-in from federation, token refresh, application access or continuation of a remembered session.

Preserve source and context

Prefer an export containing raw fields; document the interface, account or administrator role, collection time, date filters and event categories used. A filtered view can appear complete while excluding failures or application events.

Link the login to session creation and later actions. Record any preservation, reset or revocation because response activity changes the timeline.

Report at the recorded level

An accepted authentication event supports account access through the defined mechanism. Personal attribution needs the session, device and wider evidence. Preserve the IP address rather than treating derived geolocation as physical location.

The point to remember

Capture the raw login event, provenance and filters so its authentication route and resulting session can be reconstructed without relying on a simplified screen.

Reference: CLD-111Cloud Services