Cloud tenants, identity, SaaS

Cloud & SaaS Forensics

Cloud evidence moves on the provider's clock. Tenant configuration, licensing, audit settings, and provider retention decide which records exist long before an export begins.

Bagged hard drive beside a forensic write blocker.

The engagement

A source map built for the actual tenant

Cloud systems distribute evidence across identity providers, administrative portals, application logs, object storage, collaboration platforms, and local sync clients. GDF maps the data sources and retention constraints, secures supported exports, records collection parameters, and correlates events across systems.

The first task is to document the provider, subscription, regions, administrators, logging state, preservation features, connected applications, and custodians. Microsoft 365 record availability can vary by workload, license, audit configuration, retention policy, event age, and provider changes. An E5 license alone does not establish that a particular historical record exists.

Time-sensitive sources are collected first. Credentials and access are handled through the client's approved process. Examiners avoid changing tenant settings without a recorded purpose, because enabling, disabling, or remediating a control may alter later evidence.

Scope

  • Microsoft 365 and Entra

    Mailbox, message trace, unified audit log, sign-in and identity events, inbox rules, OAuth grants, administrative changes, security alerts, and supported Purview collections.

  • Google Workspace

    Mail, Drive, Chat, and administrative audit data. Login events, application-level events, and shared-drive access records preserved and correlated.

  • AWS, Azure, and object storage

    CloudTrail, S3 access logs, Azure Activity, Azure AD sign-ins, and storage account audit records preserved with collection parameters documented.

  • Slack, Teams, Box, Dropbox

    Workspace exports, channel and membership context, attached files, audit logs, retention settings, and connected services preserved where the platform supports export.

  • Cross-source correlation

    Cloud-to-endpoint and identity-to-content timelines built from provider timestamps normalized to a stated time zone. Provider identifiers retained for reproducibility.

  • Documented limits

    Where a platform cannot supply a requested field or historical period, the limitation is recorded. Collection notes distinguish what was obtained from what the system could no longer provide.

Methodology

How cloud collection runs

  1. Map

    Provider, subscription, regions, administrators, logging state, preservation features, connected applications, and custodians are documented.

  2. Preserve

    Time-sensitive sources are collected first through the client's approved access process. Collection notes record queries, ranges, options, counts, and checksums.

  3. Correlate

    Sign-ins are compared with device records, mailbox activity, file revisions, sharing events, application consent grants, IP intelligence, and endpoint telemetry.

  4. Report

    Findings are stated with sources, alternative explanations, and documented limits. Provider identifiers are retained so another examiner can reproduce the extract.

Evidence commonly examined

Evidence reviewed

  • Microsoft 365 mailbox, audit, message trace, and Entra records
  • Google Workspace mail, Drive, and admin audit exports
  • AWS CloudTrail, S3 access logs, and IAM records
  • Azure Activity, Azure AD sign-in, and storage audit records
  • Slack, Teams, Box, Dropbox, and supported SaaS exports
  • Endpoint synchronization artifacts and local caches

What you can expect

What you receive

  • Tenant source map with retention and license context
  • Preservation record with queries, ranges, counts, and checksums
  • Cross-source event timeline with time-zone conventions stated
  • Findings that separate observation from inference
  • Documented limits: unavailable fields, expired retention, provider constraints

Frequently asked

Common questions

Does an E5 license mean the record exists?

No. Record availability depends on workload, license, audit configuration, retention policy, event age, and provider changes. The source map documents what is actually available for the relevant period.

Can you preserve a cloud tenant without changing settings?

Preservation is designed to avoid changing tenant settings without a recorded purpose, because enabling or disabling a control may alter later evidence. Where a setting change is required, it is documented with time, actor, and reason.

What if a SaaS platform does not support export?

Where a platform cannot supply a requested field or historical period, the limitation is stated in the collection notes. Alternative sources, such as endpoint sync artifacts or provider-side subpoena, may be identified.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.