This is a capability which has been there for quite long time for Microsoft Account (https://account.live.com/Activity?mkt=en-US&refd=account.microsoft.com&refp=security&fref=security.cards.review-activity&uaid=9e64b34b59604f468d1cb65aa1d973b9), the ability to review sign-in activities.
Well, this is now available for corporate account (Azure AD, Office 365).
The My Sign-Ins report shows when, from which device and from where (with a map) the user has been logging on.
If unusual activities are listed, they have the ability to report back to your security team and take the appropriate actions you have teach them (change password, review MFA registration….)
There is not (yet?) a report suspicious activity option available.
This comes in addition of the existing Azure AD protection capabilities – risky users, risky sign-ins, risk detection, ATP… – which relies on Azure AD/security teams day to day work.