How do I identify whether cloud data was shared externally?¶
Separate two questions:
- Was external access made possible?
- Is there evidence that somebody actually used it?
Those are different propositions.
Reconstruct the historical permission path¶
Preserve the resource and every route that could have granted access:
- resource ID and owner;
- direct recipients;
- guest accounts;
- groups;
- inherited folder permissions;
- link ID and type;
- creation and expiry;
- authentication requirement;
- allowed actions; and
- connected applications.
A useful permission history might be:
LNK-441 created.That sequence supports more than simply finding a link in the current settings.
Current permissions may not describe the relevant period¶
A link may have been disabled later.
A guest may have been removed.
A parent-folder permission may have changed.
So use audit and permission history to reconstruct what access existed at the relevant time.
Test use separately from availability¶
Provider records may show:
- link use;
- file access;
- preview;
- download;
- external account identity;
- source address;
- application; or
- other request identifiers.
Absence of an access event needs careful wording because logging and retention vary.
What does a cloud record actually prove? is the useful companion when interpreting those fields.
Check other disclosure routes too¶
A file can leave the organisation without the original cloud object being directly shared.
Check for:
- copies;
- exports;
- email attachments;
- messaging platforms;
- synchronised folders; and
- third-party application access.
That external access was offered, to whom or through which link, and for what period.
That the external recipient opened, downloaded or retained the data unless the provider or another source records use.
The practical point is: reconstruct the permission chain first, then test whether that route was actually used.