Skip to content
Skip to main content
Cloud Services Operational Explainer

How do I identify which cloud service is involved?

Identify the provider, product, tenant and access route separately. The app name or branding visible to the user may sit above a different identity service, storage provider or security gateway, each holding different records.

Follow technical indicators without activating them

Examine full domains and URLs, application names and client IDs, account and tenant identifiers, provider-specific resource IDs, synchronisation paths, downloaded-file metadata, browser history, email notifications and password-manager entries.

Preserve URLs exactly without opening them unnecessarily. A sharing link may redirect through a tracking or security service before reaching the underlying provider, and interaction may generate new evidence.

Map the service chain

A mobile or business app may authenticate through single sign-on while storing content elsewhere. A company-branded portal may be hosted by a larger cloud platform. Personal and organisational editions of the same product can have different tenancy, logging, retention and administrator access.

Record the user-facing product, underlying data provider, identity provider, tenant or organisation and connected applications where each can be established. Identify which entity is likely to hold authentication, application, resource and administrative records.

Do not assume that the party authenticating the user also stores the data or controls the relevant audit logs. If indicators remain ambiguous, use provider documentation or specialist input before sending a request to the wrong holder.

The point to remember

Trace branding and links to the actual product, tenant, identity route and data provider so each relevant evidence holder can be identified accurately.

Reference: CLD-155Cloud Services