How do I identify who controls a cloud account?¶
Establish control for the relevant period and session, not merely account registration. Combine provider identity history with session, application, device and real-world evidence, while testing shared use and compromise.
Reconstruct changes in control¶
Start with stable account and tenant IDs, creation and recovery details, authentication methods, trusted-device history and administrator roles. Build a timeline of password resets, recovery changes, device enrolment, session creation, token activity, application consent and privileged actions.
Current settings may have changed after the event. Record when each contact, factor, permission or trusted device was added, verified or removed.
Distinguish layers of authority¶
The subscriber may own an account while another person controls a remembered or stolen session. A business identity may be administered centrally, shared by a team or used by an application. Several legitimate and unauthorised actors can be active at once.
Link the disputed event to its session and access route, then compare local browser or application artefacts, physical access, communications, work records and other independent context. State which evidence connects the technical activity to the person or organisation and which alternatives remain.
Account control can shift over time; avoid a single static conclusion where the evidence supports different controllers for different sessions.
The point to remember
Identify who controlled the specific session and authority at the relevant time, using account history, device evidence and independent context together.