Shadow IT discovery via Audit policy created under Protect for Audit has N/A as username whenever policy is matched or triggered.
This is working as expected as there are there can be multiple Users for the Service - it is currently marked as N/A. This would be removed in the upcoming version 3.162