When users are added\removed from the Restricted Group section of GPO (Computer Configuration | Windows Settings | Security Settings | Restricted Groups), the audit event for the GPO modification reports the user that is added\removed from the group incorrectly. It will repeat the username. For example, if the username is "domain\jdoe", it will display it as "domain\jdoejdoe".
The following is an example of an event recorded:
When: 3/6/2017 11:15:17 AM
Severity: Medium Severity
Who: DOMAIN\Administrator (Administrator)
What: Member DOMAIN\jdoejdoe added to DOMAIN\TestServer1 in the Restricted Groups policy DOMAIN\DC1 Test- Policy.
Action: Modify Attribute
From: <Not Set>