Thank you for posting your query on Microsoft Q&A, from above description I could understand that you are looking to tune the incidents generated on Microsoft defender portal for risky sign on attempts.
Please do correct me if this is not the case by responding in the comments section.
The only option we have as of now is to Create rule conditions to tune alerts.
However If this does not suit your business requirement then I would recommend you post your idea on our feedback forum. which is monitored by our dev team.
Please "Accept the answer (Yes)" and "share your feedback ". This will help us and others in the community as well.
Thanks,
Akshay Kaushik