Cloud tenants, identity, SaaS
Cloud & SaaS Forensics
Cloud evidence moves on the provider's clock. Tenant configuration, licensing, audit settings, and provider retention decide which records exist long before an export begins.
The engagement
A source map built for the actual tenant
Cloud systems distribute evidence across identity providers, administrative portals, application logs, object storage, collaboration platforms, and local sync clients. GDF maps the data sources and retention constraints, secures supported exports, records collection parameters, and correlates events across systems.
The first task is to document the provider, subscription, regions, administrators, logging state, preservation features, connected applications, and custodians. Microsoft 365 record availability can vary by workload, license, audit configuration, retention policy, event age, and provider changes. An E5 license alone does not establish that a particular historical record exists.
Time-sensitive sources are collected first. Credentials and access are handled through the client's approved process. Examiners avoid changing tenant settings without a recorded purpose, because enabling, disabling, or remediating a control may alter later evidence.
Scope
Microsoft 365 and Entra
Mailbox, message trace, unified audit log, sign-in and identity events, inbox rules, OAuth grants, administrative changes, security alerts, and supported Purview collections.
Google Workspace
Mail, Drive, Chat, and administrative audit data. Login events, application-level events, and shared-drive access records preserved and correlated.
AWS, Azure, and object storage
CloudTrail, S3 access logs, Azure Activity, Azure AD sign-ins, and storage account audit records preserved with collection parameters documented.
Slack, Teams, Box, Dropbox
Workspace exports, channel and membership context, attached files, audit logs, retention settings, and connected services preserved where the platform supports export.
Cross-source correlation
Cloud-to-endpoint and identity-to-content timelines built from provider timestamps normalized to a stated time zone. Provider identifiers retained for reproducibility.
Documented limits
Where a platform cannot supply a requested field or historical period, the limitation is recorded. Collection notes distinguish what was obtained from what the system could no longer provide.
Methodology
How cloud collection runs
-
Map
Provider, subscription, regions, administrators, logging state, preservation features, connected applications, and custodians are documented.
-
Preserve
Time-sensitive sources are collected first through the client's approved access process. Collection notes record queries, ranges, options, counts, and checksums.
-
Correlate
Sign-ins are compared with device records, mailbox activity, file revisions, sharing events, application consent grants, IP intelligence, and endpoint telemetry.
-
Report
Findings are stated with sources, alternative explanations, and documented limits. Provider identifiers are retained so another examiner can reproduce the extract.
Evidence commonly examined
Evidence reviewed
- Microsoft 365 mailbox, audit, message trace, and Entra records
- Google Workspace mail, Drive, and admin audit exports
- AWS CloudTrail, S3 access logs, and IAM records
- Azure Activity, Azure AD sign-in, and storage audit records
- Slack, Teams, Box, Dropbox, and supported SaaS exports
- Endpoint synchronization artifacts and local caches
What you can expect
What you receive
- Tenant source map with retention and license context
- Preservation record with queries, ranges, counts, and checksums
- Cross-source event timeline with time-zone conventions stated
- Findings that separate observation from inference
- Documented limits: unavailable fields, expired retention, provider constraints
Frequently asked
Common questions
Does an E5 license mean the record exists?
No. Record availability depends on workload, license, audit configuration, retention policy, event age, and provider changes. The source map documents what is actually available for the relevant period.
Can you preserve a cloud tenant without changing settings?
Preservation is designed to avoid changing tenant settings without a recorded purpose, because enabling or disabling a control may alter later evidence. Where a setting change is required, it is documented with time, actor, and reason.
What if a SaaS platform does not support export?
Where a platform cannot supply a requested field or historical period, the limitation is stated in the collection notes. Alternative sources, such as endpoint sync artifacts or provider-side subpoena, may be identified.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189