There are scenarios where users from different domain names get synchronized displaying duplicate accounts with two different domains, one with user@domain.com and the other with SPOTFIRE(see below screenshot).
The most common reason could be if you change the collapse domain setting AFTER a LDAP sync has already been performed. If so, it is not recommended to change the collapse domains configuration property after once having synchronized Spotfire Server with an external directory. Doing so will lead to double accounts with different domain names for every synchronized user and group in the User Directory. The new accounts will not inherit the permissions of the old accounts.
Note: If the users are logged in with default "SPOTFIRE" domain successfully but lost the permissions then you will need to grant required permissions to access the Spotfire Analyst/Webplayer or access any analysis files. However, this is not required if you want to use LDAP Active Directory.