Repeated user account created then deleted in a very short period events 4720 and 4726
During troubleshooting with the SOC team for one organization was reporting repeated AD User account Create (4720)\Delete(4726) events randomly without a specific repro scenario ,after some tests by design the user is created then the hash is compared by the password policy if it does not match the user is deleted similarly to the events below: