I’m in the same boat. This alert is a great idea, but so far I only get false positives. I believe the rules need refining.
I also get relentless false positives for impossible travel, this is even more a problem for my environment. We have workers who are travelling non stop all over the world, and this trigger fires constantly.
The error in this rule assumes people only have one device attached to them at all times..