Skip to content
Skip to main content
Cloud Services Operational Explainer

How do I identify which device was linked to cloud activity?

Match the provider's device or application record to historical management data and local artefacts from the physical device. A cloud label commonly identifies a browser profile, app installation or trusted-device object rather than hardware uniquely.

Assemble the provider-side description

Record the device ID, user agent, operating system, application/client ID, managed or trust state, session and event time. Check historical login, enrolment and trusted-device records because a device removed later may not appear in current settings.

Generic browser and operating-system details show consistency only. Devices can be renamed, restored or re-enrolled; identifiers can regenerate, while synced profiles may make several devices look alike.

Seek a cross-source match

Compare mobile-device-management data, browser profiles, application databases, local tokens, session cookies and synchronisation logs. Several stable matching values tied to the same account activity create a stronger link than one familiar name.

Where the provider record and examined hardware differ, test reset, restoration, identifier renewal or a second device using the same profile. If remote access is possible, examine remote-management records and active sessions.

Describe device linkage separately from personal attribution. Even a strong hardware match does not establish who physically or remotely operated it at the relevant time.

The point to remember

Link cloud activity to hardware through multiple historical provider and local artefacts, then keep that device conclusion separate from the identity of its user.

Reference: CLD-159Cloud Services