What should I ask a cloud provider to preserve?¶
Ask a cloud provider to preserve the specific records that matter to the investigation.
The dangerous assumption is that asking to preserve “the account” will automatically cover every useful record.
What this means in practice¶
Start with the investigative question.
Also consider whether linked services or identity providers hold separate evidence.
Where time is uncertain, use a justified range and explain why.
Where several linked accounts or tenants are possible, preserve them separately. A single email address may appear in a home tenant, guest tenant and third-party application with different records in each environment.
What this may show¶
Cloud providers may hold different categories of data in separate systems. Account details, login records, session information, audit logs, files, deleted items, application consent, billing records and support records may all follow different retention rules.
If compromise is suspected, consider authentication events, session and token activity, trusted devices, recovery changes, administrator actions, application consent and security alerts.
If file activity matters, consider file identifiers, versions, sharing, access, deletion and recycle-bin records.
What this does not show on its own¶
Do not request everything merely because it may exist. Preservation should remain relevant and proportionate.
A preservation request does not obtain the records and may not guarantee that every category is available. It helps prevent ordinary deletion while the proper process continues.
What to do next¶
Identify the account, tenant, service, date range and precise record types required.
Record the exact identifiers used, including account IDs, tenant IDs, file IDs, event IDs and known aliases.
Key takeaway
Ask the provider to preserve clearly identified, relevant record categories for the correct account, tenant and time range rather than relying on a vague request for the whole account.