The events in CloudSOC have all the user information but Enforce isn't picking up that information.
Enforce actually getting the user attributes from it's own AD integration. However, it uses the sender attributes to perform the look up. There was a change on CloudSOC side, that it had stopped sending sender email to Enforce as shown below:
As change breaks this feature as well as some policies relied on sender emails, CloudSOC reverted this change and started sending the sender email again with a hotfix deployed on August 28th 2025 3.182 Patch 3: