What should I ask an organisation that controls the cloud tenant?¶
Treat the tenant-owning organisation as an evidence holder in its own right. It may control identity, audit, security and configuration records that the provider does not retain, cannot interpret in organisational context or will not include in a standard disclosure.
Identify the systems and their owners¶
Establish which teams administer the tenant, identity platform, applications, devices, security monitoring and records retention. Relevant material may include administrator audit logs, account and role history, authentication and session records, application consent, file activity, security alerts, device-management data, help-desk tickets, backups and incident-response records.
Ask whether logs were enabled at the relevant time, how they were retained and whether copies were forwarded to a security platform or archive. A local copy may survive after the provider's equivalent has expired.
Preserve historical context¶
Current settings do not prove what applied during the incident. Seek configuration history, subscription or licence changes, retention settings, export destinations and containment actions such as password resets, token revocation or device removal.
For every export, record the operator, their role and permissions, source system, filters and time range. A limited administrator may see only part of a tenant, and a screenshot of the console may omit event-level fields or pagination.
Where compromise is suspected, build a separate incident-response timeline so investigator or administrator actions are not confused with the activity under examination.
The point to remember
The tenant owner may hold unique audit, configuration and incident records. Establish who controlled each system and what historical settings and export limits applied.