Cloud services such as Microsoft 365 operate on a distributed architecture, fundamentally different from classic IT systems installed locally within an organisation's infrastructure. User data is stored and processed in data centres belonging to the service provider, while access to it is carried out remotely – over the Internet. In practice this means that the entity using the service has no physical control over the servers or storage media on which the information is recorded.
A consequence of this model is that all information about operations performed on the data – including logins, document access, file modifications or downloads – is recorded solely in the service provider's systems, in accordance with its internal architecture and log-retention policies. Neither the end user nor the organisation's administrator has access to the source data to the extent found in traditional server systems.
The distributed nature of logs and its evidentiary significance
The Microsoft 365 architecture is based on many interoperating services, such as identity systems, e-mail, document repositories and team-communication tools. Each of these services generates its own system events and keeps separate audit logs. These logs are collected in a distributed manner and made available to administrators only to an extent depending on the permissions held, the type of licence and the prior configuration of the auditing mechanisms.
If particular audit functions were not enabled before the event occurred, data on earlier operations may not exist in a form that can be obtained later. From an evidentiary standpoint, this means that the absence of logs is not the result of their "deletion", but a natural consequence of the architecture and settings of the cloud environment.
Log retention as the boundary of event reconstruction
An important limitation of the evidentiary material is also the fact that Microsoft 365 services do not store the history of events indefinitely. Authentication logs, data-access logs and administrative-operation logs are subject to strictly defined retention periods. After they expire, the data is automatically deleted or aggregated in a way that makes detailed analysis of individual events impossible.
In practice this means that if the raw logs were not exported in time, once the retention period has passed there is no technical possibility of recovering full information about events that took place in the past. This is crucial for assessing the evidentiary possibilities in cases initiated with a delay.
Simplified data presentation and its evidentiary value
At the level of user and administrative interfaces, Microsoft 365 often presents information about account activity in a simplified or descriptive form, e.g. as "signed in a few minutes ago" or "last activity: an hour ago". This type of presentation is informational and operational in nature, not archival.
It does not always reflect the full metadata of events, such as the precise timestamp, time zone, operation identifier or session context. For this reason, printouts or screenshots from administrative panels cannot be treated as a full-value equivalent of the source data contained in the system logs.
The account, not the device – the specifics of identification in the cloud
In the cloud model, the identification of a user's actions takes place primarily at the level of the account, the session and the authentication context, rather than through an unambiguous assignment to a specific physical device. Information about devices is logical in nature and is based on data provided by the operating system or browser at the moment of login.
This is not the same as a forensic assignment of a session to a specific piece of hardware. Without simultaneously securing data from the end devices, it is impossible to unambiguously link a particular cloud activity to a specific physical device.
The IP address as an element of context, not proof of identity
Similar limitations apply to the analysis of IP addresses. An IP address recorded in the logs identifies a network connection at a given moment, not a natural person. In conditions of widespread use of dynamic addressing, NAT translation or satellite access, the same IP address may be used at different times by different devices and users.
Without operator data linked to a precise timestamp, an IP address remains merely an element of the network context of an event, and not stand-alone proof that an action can be attributed to a specific person.
Dynamic permissions and the lack of a full access history
An additional limitation of cloud architecture is the lack of a full, historical map of user permissions for every moment in time. Permissions to resources in Microsoft 365 are granted dynamically and may change frequently. The system does not store a full history of the access state unless advanced auditing and reporting mechanisms were configured beforehand.
Consequently, without the appropriate logs, it is impossible to establish unambiguously what data was actually visible or available to a user at a specific point in time.
Conclusions relevant to law enforcement
The limitations of the evidentiary material in cases involving cloud services result from the lack of physical control over the infrastructure, the distributed nature of logs, their limited retention periods, the simplified presentation of data in user interfaces, the logical – rather than physical – assignment of devices, and dependence on data that must be secured at the right time.
Understanding these conditions is crucial for a correct assessment of the evidentiary possibilities, for planning procedural activities and for properly formulating evidentiary theses in cases in which data from cloud services plays an important role.