What does a linked-device record prove?¶
A linked-device record proves, at most, that the messaging account recognised an additional device or session under the service's linking system. It does not by itself identify the physical device, its user or a particular action.
Read each field literally¶
The record may show a user-selected or generic device name, platform, link date, last-active value, session status or security state. A label such as Windows may describe software rather than uniquely identify a computer. “Last active” may mean contact with the service, not that a person read or sent a specific message.
Capture the complete record as displayed and, where available, obtain underlying account or provider data and field definitions. Absence from the current list is not proof that no earlier link existed: sessions can expire or be removed.
Build the missing associations¶
Compare session identifiers, application installations, browser data, device identifiers, IP-related records, security notifications and possession at relevant times. These sources may connect the account record to a physical endpoint and then to a possible user.
An unfamiliar entry may justify considering unauthorised linking, but it does not prove compromise. Keep three propositions separate: the account had a linked route, that route performed an event, and a named person controlled it.
The point to remember
Use a linked-device record to establish an account access route, then corroborate the physical endpoint, activity and user separately.