MCAS is enabled with MDE and AAD integration for user data enrichment. However the discovery data shows samaccountnames (domain\username) for some users and UPN for others. Both of these users are synced to AAD so how come it does not show UPN's for all users properly?

@brlgen, It's likely that the source of the data reported the user in a different way.


For example, the raw data for <this> discovered app reported <User1UPN>; but, the raw data that came into MCAS for <this> discovered app only had <User2SAMName> audited. 


The key is to look at where the data is coming from and what's being reported to MCAS. 

