What should I request from a cloud provider?¶
Request the records that answer the investigative question, not a generic package of “all cloud data”.
The dangerous assumption is that more data always produces a better investigation.
What this means in practice¶
A focused request is easier to justify, easier for the provider to understand and more likely to return usable records.
For authentication, consider login events, failed attempts, session creation, tokens, devices, applications, recovery changes and multi-factor records.
For files, consider ownership, file IDs, versions, sharing, access, download, edit and deletion events.
For administration, consider role changes, new users, policy changes, application consent, audit settings and retention actions.
The legal route, jurisdiction and provider process must be resolved through the appropriate local procedure.
Where the request is urgent, preservation may need to happen before the full acquisition request is completed.
Where the provider uses a standard disclosure form, adapt the investigative detail to that structure without losing the precise account, time and record definitions needed for the case.
What to do next¶
Identify the exact account, tenant, service, date range and activity under investigation.
Ask for provider field definitions where the terminology may be unclear.
Request raw or exportable records where available, including time zones, event IDs, session IDs, IP addresses, application IDs and resource identifiers.
Do not assume that the provider is the only data holder. The customer organisation, identity provider, backup service or connected application may hold separate evidence.
Key takeaway
Request targeted records that answer the case question, include the necessary identifiers and fields, and separate provider evidence from records held by the customer or linked services.