The ******@support.onmicrosoft.com account is logged by design today as certain operations such as SSPR and MFA registration are done. If the user has registered a strong authentication method (Multi-factor Authentication), this happens in the backend with the principal ******@support.onmicrosoft.com being the actor. This is an expected behavior.
The event occurs not only for SSPR, but can also be recorded for MFA registration, or when an admin reset the user's password.
Let me know if this helps answer your question.