My guess is that they are not "logging in" they are simply "authenticating" which is a big difference. To gain access to resources you normally only need proper credentials.

You really need to implement Management policies against this if you really want to control these systems.