APCPR03A001 is just the "server/domain" prefix. Most, if not all of your users will have the same value. And joe12345678912345 is the samaccount name, so what you are seeing is the user identifier in the domain\samaccountname format. To get the matching user object, use Get-User, for example this is my account:
Thanks for that, makes a little more sense now. So even with our own AD environment, 365 creates another SAM account on the 365 servers? It looks like these SAM account name that appeared in the audit are old users that have been deleted so they do not resolve with get-user. Is there any other way to resolve who these users are?