Skip to content
Skip to main content
Cloud Services Technical Explainer

What can cloud records prove about a device?

Cloud records can associate activity with a provider-defined device, browser, application installation or trusted-device object. Whether that identifies one physical device depends on how the provider creates and maintains the identifier.

Identify what the field represents

Useful attributes may include device ID, operating system, browser or user agent, application, enrolment, managed status and trust state. Some IDs survive many sessions; others reset with cookies, reinstallations, browser profiles or device restoration. A generic browser-and-operating-system combination is not unique.

Historical login, enrolment and trust records may be more informative than a current device list, which can omit removed devices. Preserve the provider definition and the time each attribute applied.

Bridge the cloud object to the physical device

Compare several fields with mobile-device-management records, local browser and application artefacts, session material and forensic examination. Matching stable identifiers across independent sources gives a stronger link than a familiar display name.

If cloud and physical evidence disagree, retain the competing explanations. The identifier may have regenerated, the device may have been restored, or another device may have used the same synced profile. A physical device may also be shared, stolen or remotely controlled.

Describe the conclusion at the supported level: the event was associated with a defined provider device record, followed by the evidence linking that record to the examined hardware. Device attribution still does not prove which person operated it.

The point to remember

Understand the provider's device object, then match it to historical and local evidence before treating it as one physical device.

Reference: CLD-142Cloud Services