What should I do when I encounter a live cloud session?¶
A live cloud session may provide temporary access to files, records and account information held somewhere other than the device in front of you.
Avoid this assumption: A logged-in cloud page can be explored like a local folder. Navigation may create audit records, change recent activity, trigger synchronisation or alert other users.
First, record the session as found. Capture the service, URL, account, tenant, workspace, organisation, visible page, date, time and device context.
Note whether the session appears fully online, cached, offline, remotely accessed or open inside a virtual machine.
Preserve visible folder names, filenames, document IDs, sharing indicators, version information, deleted-item notices and security warnings.
Do not refresh, download, open, move, rename or delete cloud content merely to inspect it.
Do not log out or change credentials automatically. That may terminate access, remove local cache or alert another user.
Consider whether other users may still be editing or deleting material remotely.
Where the evidence is volatile, business-critical or central to an active incident, seek cloud, provider or forensic support quickly.
Record any unavoidable interaction and distinguish the original state from later changes.
Remember that the device may only be a route into the evidence. The provider, organisation and linked accounts may hold the more complete record.
Record whether the session is personal, organisational, delegated or administrative, because different users may have different rights to view, change or preserve the material.
Operational takeaway¶
Preserve the live cloud session, account and page context before navigation, and treat every open, download, refresh or logout as a potential evidential change.