What is a cloud-resource identifier?¶
A cloud-resource identifier is a value used by the provider to distinguish a specific file, account, object, folder, virtual machine, mailbox or other cloud resource.
It is usually more reliable than the visible name alone.
What this may show¶
Names can be changed, duplicated or reused. A stable internal identifier may remain consistent across moves, renames and some ownership changes.
Investigators should preserve the full identifier exactly as recorded.
A restored file may look identical but carry a different identifier. An older version may share the same file ID but have a separate version ID.
Where several services are linked, each may assign its own identifier to the same underlying content or account.
Use the identifier to connect precise events and avoid relying only on filenames or display names.
When documenting the evidence, record both the human-readable name and the provider identifier. The name explains the context; the identifier protects against confusion with renamed or duplicate resources.
If a provider export contains both a parent identifier and a child resource identifier, preserve both. The relationship may explain which folder, account or service contained the object at the relevant time.
What this does not show on its own¶
The dangerous assumption is that two resources with the same name are the same object.
What to do next¶
Check whether the identifier is global, tenant-specific, version-specific or linked to a parent resource.
Compare it across audit logs, activity records, exports, version history and provider disclosures.
Do not assume that every identifier remains stable forever. Copying, restoring, migrating or recreating a resource may generate a new value.
Key takeaway
A cloud-resource identifier helps distinguish the exact object involved, so preserve it unchanged and establish whether it remains stable across versions, copies and restores.