What should be preserved from cloud audit or activity records?¶
Preserve event detail together with the service, tenant, viewer role, filters, time range and completeness limits that define what the list can show.
Record technical event identity¶
Capture event type and ID, actor account, target object, timestamp and timezone, device, browser, network, location, session and success, failure or administrative status.
Preserve pagination, export limits, delay, sampling and retention warnings before changing filters or sort order. Document each later query so it can be reproduced.
Audit actors still require attribution¶
Shared accounts, delegates, applications, scripts and compromised sessions can appear as the actor. Separate investigator-created events from earlier activity.
For central evidence, obtain native provider records rather than relying only on a screenshot; absence from a limited view does not prove no event occurred.
Key takeaway
Preserve audit events with their query scope and limitations, then corroborate the technical actor before attributing conduct to a person.