We could use session history stats (when was the last time the user logged in?, how often did logins fail? and similar). All in accordance with our privacy standards, of course.
https://apereo.github.io/cas/6.0.x/installation/Configuring-Authentication-Events.html
https://apereo.github.io/cas/6.0.x/installation/Audits.html