Purpose
Explain the mismatch
Determine which identity, storage location, sync relationship, item restriction, permission, or migration boundary matches the symptom.
Microsoft 365 / OneDrive / SharePoint / Investigation
Identify the authoritative location, compare web and local evidence, and explain the failed boundary before changing client state. This is an investigation guide, not a repair, migration, or data-reconciliation procedure.
Purpose
Determine which identity, storage location, sync relationship, item restriction, permission, or migration boundary matches the symptom.
Boundary
No accounts, credentials, relationships, files, permissions, retention settings, or OneDrive configuration are changed by this guide.
Examples
alex.taylor@example.com, Example Research, and Project Atlas are documentation-safe placeholders.
Method
Compare the intended cloud location with the actual local root and the account shown by the OneDrive sync app.
1 · Investigation question
Determine where the expected item should live, where each observed copy actually lives, whether the correct account and relationship are active, and whether the evidence points to access, client state, an item restriction, storage pressure, or post-migration drift.
Separate browser access, library availability, local folder visibility, individual-item synchronization, and Office application behavior.
Establish whether one item, one folder, one library, one device, one user, or every synchronized location is affected.
A status icon or matching name alone does not prove that every expected item and byte is present in both locations.
2 · Safety boundary
Synchronization is not a backup. A change made in a synchronized folder can propagate to the cloud and other devices. Record the exact paths, identity, activity state, errors, timestamps, and local-only data before proposing remediation.
A green status icon does not prove every expected file is present and current. A duplicate folder must not be deleted until its identity, relationship, and contents are verified.
Do not collect passwords, tokens, browser cookies, authentication databases, Windows credential secrets, private tenant URLs, or customer identifiers.
3 · Source of truth
Ask the data owner where work is supposed to occur now: the user's OneDrive, a SharePoint document library, a local-only folder, an approved migration destination, an older source, or another user's synchronized copy. Record the decision and its owner.
Do not use the newest timestamp, a green icon, or whichever folder is easiest to reach to guess which version is authoritative. Web, local, migrated, and other-device copies must be compared before reconciliation.
4 · Symptom record
Identity
Record synthetic user and device labels, the expected Microsoft 365 account, and the exact account currently shown in OneDrive.
Cloud
Record the SharePoint site, document library, browser location, whether the item exists, and whether it opens successfully.
Local
Record expected and actual sync roots, the file or folder name, local location, size, modified time, and Files On-Demand icon.
Client
Record whether sync is running, paused, signed out, or showing an error, plus the exact displayed activity and error text.
Scope
Record whether one item, folder, library, or every location is affected and whether other users or devices reproduce it.
Context
Record available local disk space and known migration, account, permission, rename, move, Windows-profile, or device changes.
5 · Web versus local
Record whether the item exists in each location, whether both copies open, their sizes and modified times, available version history, content differences, Files On-Demand state, and any pending or failed indicator.
A file visible locally does not prove it reached OneDrive or SharePoint.
A file visible in the browser does not prove it synchronized to this device or every other device.
Matching filenames do not prove matching content. Open and compare the intended document where authorization permits.
Modified timestamps alone should not determine which version replaces another.
Whole-file hashes prove whether bytes match. Different hashes for Office documents require careful interpretation because document content, properties, or package metadata can differ; preserve both copies and use content-aware comparison before drawing a conclusion.
6 · Signed-in identity
Select the OneDrive cloud icon in the Windows notification area, open OneDrive settings, and review the accounts and organizations displayed. Microsoft supports multiple work or school accounts, so do not assume the visible folder belongs to the expected organization.
Compare the expected account with the account listed for the affected relationship.
Record every connected work or school organization and which local root belongs to each.
Record only the minimum account label needed for the private case. Never collect credentials, cookies, tokens, or authentication secrets.
7 · Local root
Record the full local path and organization label. Determine whether it belongs to the user's OneDrive, a device-specific SharePoint library sync, a shortcut surfaced through OneDrive, a manually copied folder, a migrated destination, or an obsolete Windows profile.
Account names, site names, library names, and organization folders can look alike while resolving to different locations. Duplicate organization folders are evidence to identify—not automatic deletion targets.
8 · Architecture
Work or school storage associated with that user's account. Its File Explorer root normally includes the organization name.
The OneDrive sync app connects a selected SharePoint document library to this particular device.
A SharePoint or shared-folder shortcut appears in the user's OneDrive and can follow the user across devices. It is not the same topology as device-specific Sync.
A copied folder outside an active root does not gain synchronization merely because its name resembles a library.
A destination becomes authoritative only through the approved migration decision and cutoff—not because a sync relationship exists.
9 · Files On-Demand
A blue cloud means the item is available online and downloads when opened. It is not necessarily missing or unhealthy.
A green check indicates the item has downloaded and can be opened offline; storage management can return it to online-only.
A solid green circle with a white check means Always keep on this device is selected and the item consumes local space.
Circular arrows mean synchronization is in progress or pending. Record how long the state persists and the related activity text.
A red circle with a white cross means an item cannot synchronize. Open the OneDrive activity area and record the exact item and error.
10 · Known Folder Move
Known Folder Move protects Windows Desktop, Documents, and Pictures by moving them into the user's OneDrive. It does not redirect Windows Documents directly into a SharePoint document library. Record whether the observed path is the user's OneDrive known folder, an ordinary local folder, or a separate SharePoint relationship.
11 · Access
Test access in the browser before treating the client as the cause. Record whether the user cannot reach the site, can view but not edit, can use the web library but cannot see it locally, or can synchronize the library except for one item.
Investigate identity, site or library permissions, licensing, sharing boundaries, or service availability before client state.
Investigate whether the correct relationship and folders are configured for this account and device.
Investigate its name, path, size, lock, checkout, metadata, permissions, or applicable security and compliance controls.
Confirm the effective permission and whether checkout, validation, draft security, retention, or sensitivity behavior is involved.
12 · Restrictions
Compare the exact item against Microsoft's current restrictions for invalid characters, reserved names, decoded path length, individual file size, item-count and performance considerations, unsupported content, permission requirements, and library or tenant settings.
This guide intentionally does not reproduce fixed numeric limits. Use Microsoft's maintained Restrictions and limitations in OneDrive and SharePoint during the investigation.
13 · Client evidence
Select the relevant OneDrive cloud icon in the Windows notification area. Record the displayed identity, whether synchronization is current, processing, paused, signed out, or in error, the affected item, current activity, and exact message. Confirm the OneDrive process is running and compare the same item in the browser.
Capture exact text and timestamps rather than paraphrasing a transient notification.
Record which organizations and locations appear in OneDrive settings without collecting secrets.
Keep available Windows or OneDrive diagnostic evidence in the approved private case location. Do not publish logs or tenant details.
14 · Duplicate roots
Duplicate organization or library folders can result from another account, an older Windows profile, a changed organization label, a shortcut, a re-established sync, or a manually copied tree. For each root, record its path, account, relationship type, cloud destination, item count, recent activity, and local-only differences.
A stale-looking folder may contain unsynchronized work. Preserve evidence and confirm that a root is inactive before routing any cleanup through a separately approved procedure.
15 · Post-migration drift
Record the migration cutoff, approved destination, old source, affected user and path, and all changes made after cutoff. Preserve both versions while comparing size, timestamps, version history, hashes, and document content.
Bulk overwrite is unsafe. File movement can destroy timestamps, version context, sharing relationships, or conflict evidence.
Document every conflict and exception. Copy, overwrite, restoration, or reconciliation requires a separate approved migration procedure with ownership, backups, change control, and verification.
16 · Evidence correlation
| Observation | What it may indicate | What it does not prove | Safest next investigation step |
|---|---|---|---|
| File exists in SharePoint but not locally. | The folder is not selected, the relationship is absent or stale, or an item restriction blocks it. | That the cloud file is lost or the client must be reset. | Confirm identity, relationship type, sync root, folder selection, activity, and exact error. |
| File exists locally but not in SharePoint. | A local-only copy, pending upload, failed item, wrong root, or old profile. | That it is safe to move, delete, or force-upload. | Preserve it and identify the root, account, intended destination, and error. |
| Both locations have different content. | Divergent edits, stale sync, conflict handling, or post-migration drift. | Which copy should replace the other. | Preserve both and compare ownership, history, content, hashes, and cutoff evidence. |
| Browser access works but local sync does not. | A client, account, selected-folder, relationship, device, or item restriction. | That permissions and identity are correct for editing every item. | Record effective web behavior, client identity, local root, activity, and scope. |
| User is signed into the wrong organization. | The visible root may belong to another work or school account. | That the other account or its data can be removed. | Map every account and root to its organization and cloud destination. |
| Duplicate organization folders exist. | Multiple accounts, profiles, shortcuts, relationships, renamed organizations, or copied data. | That either folder is stale or disposable. | Inventory identity, relationship, destination, activity, and local-only data for each. |
| One library fails while others synchronize. | A library relationship, permission, setting, volume, or item set is specific to the failure. | That OneDrive is globally unhealthy. | Compare the failing library with one working library under the same identity. |
| One file fails while the library synchronizes. | A name, path, size, lock, checkout, permission, metadata, or content restriction. | That the library relationship must be rebuilt. | Compare the item with current Microsoft restrictions and its browser behavior. |
| A blue cloud is mistaken for missing data. | The item is online-only under Files On-Demand. | That it is available offline or current on every device. | Confirm it opens in the browser and record its actual status and sync activity. |
| Synchronization remains pending. | Queued work, open files, connectivity, storage, a restriction, or client processing. | That waiting indefinitely or resetting will preserve every local change. | Record duration, activity, affected scope, disk space, and exact errors. |
| Local disk space is constrained. | Downloads or client work may be unable to complete. | That cloud content is missing or local data is safe to remove. | Record capacity and Files On-Demand state, then route capacity remediation separately. |
| An invalid-name or path error appears. | The item conflicts with a maintained OneDrive or SharePoint restriction. | That every item or the entire library is affected. | Compare the exact item and full path with Microsoft's current restrictions. |
| Permissions changed recently. | Access or edit capability may differ from the established local relationship. | That the client cached the wrong credential or should be unlinked. | Verify browser access and effective permission with the site owner. |
| An old Windows profile has the expected files. | Work may remain in an obsolete or unsynchronized local root. | That the files reached the approved cloud destination. | Preserve the profile data and compare it with the authoritative cloud location. |
| Post-migration edits exist in the old location. | Users continued working after cutoff or the workflow transition was incomplete. | That bulk overwrite is safe. | Build an approved exception inventory and route reconciliation separately. |
17 · Escalation
Conflicting versions have unclear ownership, possible data loss exists, or backups and recovery capability are missing or unverified.
Multiple users or libraries are affected, or evidence suggests a tenant-wide Microsoft 365 service issue.
Large-scale post-migration drift or any bulk copy, overwrite, deletion, restoration, or migration is required.
Retention, sensitivity, legal hold, records management, or another compliance control may govern the item.
Ransomware, unauthorized mass changes, compromise, or unexplained broad modification is suspected.
An unknown profile, credential cleanup, reset, unlink, account removal, library removal, or shortcut removal is required.
18 · Intentionally excluded
Excluded actions include resetting OneDrive; unlinking the computer; signing users out; removing accounts, credentials, configuration data, sync roots, library relationships, or shortcuts; editing the registry; renaming, moving, deleting, restoring, bulk-copying, or overwriting production files; deleting duplicate folders; changing permissions, Files On-Demand, Known Folder Move, retention, sensitivity, or compliance settings; reinstalling OneDrive; and resolving conflicts automatically.
These actions require separate authorization, verified backups, confirmed ownership, change control, and an environment-specific remediation plan.
19 · Related resources
Learning method
Keep evidence collection in the investigation phase before authorizing a change.
Review the learning pathTopic hub
Connect SharePoint and OneDrive behavior with identity, access, and collaboration boundaries.
Open the Microsoft 365 hubRelated investigation
Use the Entra guide when sign-in or Conditional Access evidence may explain access behavior.
Open the Entra guideTutorial catalog
Browse the complete set of published KrippyTech investigations and procedures.
Browse tutorialsMicrosoft sources