A company name is not a cloud boundary. One enterprise may retain several email tenants after acquisitions, use outside administrators and operate business applications with separate identities. Start collection planning by mapping those boundaries. Otherwise, a successful export from the main tenant can hide an entire missing business unit.
Create one register of sources and owners
List each provider and tenant with its business owner, authorized administrator, relevant accounts and collection purpose. Record subscriptions, regions, connected applications and providers responsible for logs or backups. Do not place credentials in the evidence inventory; handle access through the client's approved secure process.
Compare the register with identity directories, application inventories, acquisition records and business owners. Ask specifically about retired tenants, unmanaged workspaces and transition-service arrangements. A system that is no longer used for daily work may still contain the relevant historical period.
Prioritize the records that will disappear first
Content, audit and identity records can have different retention conditions. Microsoft Purview availability depends on the applicable features and configuration; Google Workspace also distinguishes audit sources and administrative capabilities. Verify the actual records and period available. A current license cannot establish that an older event was retained.
- State the required period and the period the source can actually supply.
- Separate holds from exports and document what each action protects.
- Identify expiring administrator access or provider contracts.
- Record collection permissions without broadening them unnecessarily.
- Assign unresolved access and retention questions to named owners.
Define completion before launching exports
Specify expected accounts, data types, filters and delivery format. Retain queries, manifests, counts, timestamps and errors. Check output integrity and representative records, then reconcile the result against the register. A zero-result export may reflect a filter, permission or retention problem; validate that explanation before declaring the source empty.
Keep original provider identifiers when joining records across systems. Normalize timestamps while retaining their raw values. Where logs cannot support a conclusion about access or transfer, state that boundary directly rather than filling the gap with certainty.
For acquisition methods, see cloud evidence collections. For downstream checks, see collaboration collection reconciliation. GDF's eCloud Discovery page describes the software separately from the scope and limitations of a particular engagement.