What is persistence in a cloud account?¶
Persistence is an access route or automated effect that survives after the original login or credential is removed. It can let an actor regain control, continue receiving data or operate without an interactive session.
Persistence takes several forms¶
Examples include additional administrators, delegated permissions, application consent, long-lived tokens, API keys, service accounts, trusted devices and changed recovery methods. Forwarding, sharing and automation rules can continue moving data even after the person loses direct access.
The foothold may sit outside the main service - in a linked identity provider, external application or delegated tenant - so follow the complete authority chain.
Trace creation, use and removal¶
For each mechanism, preserve its stable identifier, permission scope, creator account or session, creation time, configuration and activity. Compare administrator audit, consent, token and application records with expected organisational changes.
Unfamiliar configuration is not automatically malicious. Establish whether it was approved, what it could do and whether it was actually used.
Before removal where operationally possible, capture the state and related logs. Record the exact control used, time and subsequent activity so containment can be tested. Changing only the password leaves many persistence routes unaffected.
The point to remember
Cloud persistence survives the original credential through roles, tokens, applications, rules or recovery paths; identify and verify each route separately.