What should I do first when cloud evidence may be relevant?¶
Define the decision the evidence could affect, identify the likely service and evidence holders, and assess what may disappear or be altered. The first useful action is often targeted preservation - not an attempt to obtain every item from a provider.
Establish the technical scope¶
Record known account, tenant, application, file, session and device identifiers, the relevant period and time zone, and actions already taken. Clarify whether the question concerns account use, access, sharing, deletion, session-to-device linkage or another defined event.
Map the sources: the provider may hold account and audit events; the tenant organisation may hold administrator logs, alerts and backups; devices may contain local copies, browser artefacts, tokens and synchronisation records.
Protect fragile evidence before interaction¶
Login, session, token, deleted-item, alert and audit records can have short retention. Prioritise the volatile source most likely to affect the decision and document that choice.
Opening links, signing in, restoring items or reconnecting devices may generate events, trigger sync or notify others. Separate preservation, collection and containment as distinct actions with their own evidential effects.
Where the environment is live, compromised or technically complex, seek specialist support early. Avoid unnecessary interaction while responsibility and a controlled plan are established.
The point to remember
Begin with the decision, sources and volatility, then preserve the most fragile relevant records before changing the live cloud environment.