Skip to content
LOG-130 Logs, Records & Provider Evidence

Could different account tiers retain different records?

Yes. Different subscription, licence or account tiers can retain different types and lengths of log data.

The same provider may therefore offer very different evidential opportunities to different customers.

Avoid the dangerous assumption

The dangerous assumption is that if one organisation can obtain a certain record from a service, every customer of that service can obtain the same thing.

That may be wrong.

A basic tier may keep only recent sign-in history. A higher tier may retain detailed audit, security, mailbox, API or administrator events for longer. Some advanced records may never be generated unless the relevant feature was licensed and enabled.

Retention can also change when an organisation upgrades or downgrades. Historical data may not appear retrospectively simply because a higher tier is purchased later.

Investigators should identify the exact product, tenant, licence and features that applied during the relevant period. Ask which records were generated by default, which required configuration and how long each type was retained.

Do not rely only on current marketing material. The provider’s features and retention rules may have changed since the event.

Preserve screenshots or documentation showing the applicable tier and settings where proportionate. Ask whether data was exported to a SIEM, archive or backup before provider retention expired.

A missing record may therefore mean it was not licensed, not enabled or not retained, rather than deleted.

Operational takeaway

Account and licence tiers can determine which records exist and how long they remain available, so investigators must establish the exact service level and configuration that applied at the relevant time.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.