What is a device identifier in a cloud record?¶
A device identifier is a value the cloud service or linked identity system uses to distinguish a registered or observed device.
It may support analysis of which device was associated with a login or session.
What this means in practice¶
Investigators should identify who generated the value, what it represents and whether it is stable across sessions.
What this may show¶
Identifiers can be reset, regenerated, reused by applications or changed when the device is re-enrolled, reinstalled or restored.
Some providers create their own identifier for a browser or app installation rather than for the hardware itself.
Where the provider records device trust, compliance or management status, preserve those fields separately.
Historical identifiers may be more useful than the current trusted-device list. A device removed from the account can still remain relevant to earlier sessions and events.
Where device enrolment or management systems are involved, obtain the registration and removal history. That history may show when the device first became trusted, when its status changed and whether the identifier was reassigned.
What this does not show on its own¶
The dangerous assumption is that every device identifier uniquely and permanently identifies one physical device.
Equally, a changed identifier does not automatically mean a different physical device.
What to do next¶
Preserve the exact identifier, account, session, application, time and related device information.
Compare it with mobile-device management records, trusted-device lists, browser profiles, application databases and forensic device evidence.
Do not assume that a matching identifier proves the account holder possessed the device. The device may be shared, stolen, remotely accessed or controlled by another person.
Key takeaway
A cloud device identifier links activity to a provider-defined device record, so establish what the identifier represents before using it for physical-device or personal attribution.