Urgent Security Incident – Unauthorised Global Administrator / Partner Delegated Administration Activity

Gregory Bond 0 Reputation points
2026-09-07T22:33:50.8166667+00:00

Our Entra audit logs show that on 5 September 2026, a temporary account was created by an identity recorded as CentralNic Group Australia Technician. The same actor then successfully assigned that account the Global Administrator role.

Shortly afterwards, the account registered Microsoft Authenticator, participated in partner/delegated administration activity, and was then deleted approximately two and a half minutes after creation.

We have also identified related delegated administration / cross-tenant activity associated with the CentralNic partner relationship.

We do not currently have an explanation for this activity and did not knowingly authorise the temporary Global Administrator account.

What action should be taken for this unauthorised activity?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Newest
  1. Abdul Waqas 0 Reputation points
    2026-09-08T17:45:29.1+00:00

    Hi,

    I would treat this as a potential privileged-account compromise or unauthorized delegated administration activity until the activity is confirmed.

    Immediate containment: If the activity is not authorized, immediately disable the affected account, revoke its active sessions/tokens, and temporarily suspend the associated delegated administration access while preserving the audit evidence. Avoid deleting anything until the investigation is complete.

    I recommend:

    Review Microsoft Entra Audit and Sign-in logs around 5 September 2026. Check who created the account, assigned Global Administrator, registered MFA, and deleted the account.

    Review the CentralNic partner relationship/GDAP configuration and confirm whether the delegated access was authorized.

    Check Authentication Methods, Enterprise Applications, service principals, and consent activity for unexpected changes during the same period.

    If unauthorized changes are found, remove unexpected privileged roles or access after preserving the evidence.

    Open a Microsoft Support/security incident with the relevant timestamps, audit records, relationship details, and correlation IDs.

    The fact that the account was created, granted Global Administrator, registered MFA, participated in delegated administration activity, and was deleted within roughly 2.5 minutes makes the immediate containment, audit-log review, and GDAP investigation the priority.

    Please do not share Tenant IDs, User IDs, or other sensitive information publicly.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.