Thanks for the tip. The script below uses Graph API to check for a cloud user matching the user that was just disabled.
# concatenate admin account
$adminuser="admin-%firstname%.%lastname%@yourdomain.com"
#connect to Graph API
$token = $Context.CloudServices.GetAzureAuthAccessToken("https://graph.microsoft.com")
$token = $token | ConvertTo-SecureString -AsPlainText -Force
Connect-MgGraph -AccessToken $token
# E-mail settings
$to = "support@yourdomain.com"
$subject = "Admin User Found"
if ( Get-MgUser -UserID $adminuser) {
$body = "User %username% has been disabled and a matching administrator account was found: admin-%firstname%.%lastname%. Check if this adminstrator account also needs to be disabled!"
$Context.SendMail($to, $subject, $NULL, $body)
}