A cloud-based identity and access management service for securing user authentication and resource access
Hi,
I would treat this as a potential privileged-account compromise or unauthorized delegated administration activity until the activity is confirmed.
Immediate containment: If the activity is not authorized, immediately disable the affected account, revoke its active sessions/tokens, and temporarily suspend the associated delegated administration access while preserving the audit evidence. Avoid deleting anything until the investigation is complete.
I recommend:
Review Microsoft Entra Audit and Sign-in logs around 5 September 2026. Check who created the account, assigned Global Administrator, registered MFA, and deleted the account.
Review the CentralNic partner relationship/GDAP configuration and confirm whether the delegated access was authorized.
Check Authentication Methods, Enterprise Applications, service principals, and consent activity for unexpected changes during the same period.
If unauthorized changes are found, remove unexpected privileged roles or access after preserving the evidence.
Open a Microsoft Support/security incident with the relevant timestamps, audit records, relationship details, and correlation IDs.
The fact that the account was created, granted Global Administrator, registered MFA, participated in delegated administration activity, and was deleted within roughly 2.5 minutes makes the immediate containment, audit-log review, and GDAP investigation the priority.
Please do not share Tenant IDs, User IDs, or other sensitive information publicly.