Could reconnecting a device trigger cloud synchronisation?¶
Yes. Reconnecting a device can trigger immediate cloud synchronisation that changes both local and provider-held records.
Avoid this assumption: Reconnection simply restores access. The device may upload queued files, download newer versions, apply deletions, refresh permissions or replace cached content.
A locally preserved file may be overwritten by the cloud version. A deleted cloud item may disappear from the device. An unsynchronised local item may upload and create a new provider event.
Before reconnection, record the device, account, application, visible files, sync indicators, timestamps, connectivity and any offline or pending status.
Capture warnings about conflicts, failed uploads, paused synchronisation or storage limits.
Do not reconnect merely to see whether the cloud account still works.
Consider whether provider preservation, specialist capture or a controlled copy of local material should occur first.
If reconnection is necessary, use a controlled network and record the exact time, method, device and account.
Capture the screen immediately before and after connectivity returns.
Record uploads, downloads, version changes, deleted items, permission changes, login prompts and security alerts.
Be alert to remote-management or wipe commands that may also arrive.
Do not assume that the time of synchronisation is the time the underlying file was created, edited or deleted.
Record whether the synchronisation application starts automatically at login or reconnection, because the evidential change may occur before the investigator can interact with it.
Operational takeaway¶
Treat cloud reconnection as a major synchronisation event, preserve the offline state first and document every upload, download, deletion and version change that follows.