@brlgen, It's likely that the source of the data reported the user in a different way.

 

For example, the raw data for <this> discovered app reported <User1UPN>; but, the raw data that came into MCAS for <this> discovered app only had <User2SAMName> audited. 

 

The key is to look at where the data is coming from and what's being reported to MCAS. 

www.000webhost.com