yes, we are using SAML authentication, with DUO and Azure AD for MFA. The User column just displays the word email. One thing I noticed, only one Anyconnect vpn user will show connected in network- wide clients, unless I search for the anyconnect ip address that was assigned, I can see the ip addresses assigned in the event log. Also, each Anyconnect connection shows the same description, which looks like a MAC address. and in the MAC address column, it shows N?A (Anyconnect VPN), or if they are connected to the client vpn, it shows N?S (Client VPN)
We have the firmware version MX 18.107.5