What should I ask an organisation that controls the cloud tenant?¶
Ask the organisation for the records, configuration and context it controls within the cloud tenant.
The dangerous assumption is that only the cloud provider can supply useful evidence.
What this means in practice¶
Start by identifying who owns the tenant and which team controls identity, security, applications and records management.
Where compromise is suspected, ask about containment actions, password resets, token revocation, device removal and incident-response timelines.
Also ask whether logs were enabled, how long they are retained and whether any filters were applied to the export.
The organisation may also hold local copies forwarded into a security platform or archive. Those records can survive after the equivalent provider log has expired.
What this may show¶
The customer organisation may hold administrator audit logs, identity records, security alerts, device-management data, retention settings, help-desk tickets, backups and exported reports.
Organisational records may need to be preserved quickly before ordinary retention or system changes remove them.
What to do next¶
Ask for the relevant account and role history, authentication and session records, administrator actions, file activity, application consent and policy changes.
Request the historical settings that applied during the event, not only the current configuration.
Do not assume that an administrator’s screenshot is the complete record. Seek raw exports and field definitions where available.
Ask who performed the export and what permissions they held. Limited administrator roles may see only part of the tenant’s audit, identity or security information.
Key takeaway
Treat the tenant-owning organisation as a separate evidence holder and request its audit, identity, security, configuration and incident-response records alongside any provider material.