Technical Case · KT-000025

External Repair Required a Data-Custody Plan

A device needed to leave organizational control for hardware repair. The technical job was not only to ship the endpoint.Cloud access, local cached data, continuity, and the post-repair rebuild all had to be controlled.

Case ID

KT-000025

Category

Endpoint Repair & Data Custody

Status

Data Protected / Repair Continuity Verified

Technologies

Windows / OneDrive / SharePoint / Endpoint Repair

Investigation

How was the custody change handled?

External repair is a custody change. Protect the data before the hardware leaves organizational control.

Removing an application is not proof that synchronized business data is gone.

Investigation path: Repair decision → Continuity check → Stop sync → Unlink cloud relationships → Remove local cached data → Verify absence → Transfer custody → Factory-reset return → Known-good rebuild → Reconnect required libraries

Step 1

Protect continuity before changing custody

The user requested removal of access to sensitive shared libraries before shipment. A separate endpoint preserved business continuity before the repair device left organizational control.

Step 2

Stop synchronization and unlink cloud relationships

Sync activity was allowed to stop before removal was treated as complete. OneDrive and SharePoint relationships were disconnected before custody transferred.

Step 3

Verify local cached-data removal

Local synced content was cleared from the endpoint as intended, and its absence was checked separately from removal of the sync application.

Step 4

Rebuild from the returned state

The repaired device returned in a factory-reset state. A known-good rebuild re-established required applications and reconnected only the required cloud libraries.

Finding

What was actually proven?

The repair workflow had to include data protection

Uninstalling OneDrive or another sync client alone does not prove local business data is gone. The supported sequence stopped sync, unlinked the relationships, cleared the intended local content, and verified absence before transfer.

This page is the proof layer for a documented custody change, not a replacement for the linked change-safety, workstation, or verification methodologies. The hardware defect itself is not the lesson.

Evidence boundary

This case does not claim every repair depot uses the same custody procedure, that the repair provider was untrusted or malicious, or that every repair requires the same alternate-device continuity method.

It does not claim all browser data, local credentials, application caches, secrets, encryption state, MDM controls, wipe operations, or remote-reset controls were addressed; those controls require separate evidence.

Public-safe boundary

This case does not publish customer, repair-provider, device, tenant, library, account, or identifying system details.