When I checked the Azure activity logs, I noticed that an account that is not in our AAD user list was updating the incidents. Does anyone know why this is happening?
Not sure if you've managed to find the answer yourself. I couldn't verify this anywhere in official MS documentation, so take the below with a pinch of salt!
This is an account (Caller) used by MS/Azure health service to communicate and push updates regarding ongoing, service-affecting incidents. Same official comms can also be found here: https://azure.status.microsoft/en-us/status/history/