I recently had an error message pop up synchronizing from our on-prem AD servers to Entra about an account issue. I found that the account in question had all the attributes correct except for the userPrincipalName. In the UPN, instead of having the username@mydomain.com, it was changed to a "\"@mydomain.com. I am trying to figure out who or which account made that change in Splunk Cloud. I have searched for Event IDs 4738 and it shows the UPN with the "\" but it doesn't tell me who made the change. Also I am looking in the Windows TA addon to see if I can find any more info in there.