We are starting to see a lot of unwanted access escalations. Maybe this is not such a big issue in the US, but for europeans who travel a lot between our tiny countries, this is like americans receiving an Unwated Access escalation every time one of their users travel to a different US state, or even a different city.
One way to greatly reduce the amount of notifications would be to cross-check the MDR locations with those seen in the EDR, or even on devices pulled through the Microsoft Graph API.
Because if an account AND a PC is in use on the same IP / same strange country, then it's highly likely that it's just the user who's out travelling, and not actually unwanted access.