Hello,
if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with "o365_address_ranges" and if needed other networks as member.
Doing so, all traffic to o365 will be routed via the security gateway.
if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.
as therock mentioned, having multiple ... "VPN profiles" you might likely run into limitations.