@brlgen, It's likely that the source of the data reported the user in a different way.


For example, the raw data for <this> discovered app reported <User1UPN>; but, the raw data that came into MCAS for <this> discovered app only had <User2SAMName> audited. 


The key is to look at where the data is coming from and what's being reported to MCAS.