Looking in Investigate in CloudSOC, there are very few if any Login events for users logging into Office 365
Login to Office365 is being handled by an IDP
Direct login events to Office365 are RequestType Login. If users are logging into an IDP such as PingFederate that handles the authentication then authenticates the user to Office365, the RequestType in Office is shown as Federate. CASB does not recognize the RequestType of Federate as a login event.
This has been requested as an enhancement to CASB.