I haven't tried it myself but I was reading about it in forums and actually to be able to try it out, you will need to have a company with large number of PCs. One concern which some people raised is because it is inside Microsoft Cloud, they might not want to share data on cloud and as public cloud and they want private cloud and use it inside their own data center which is not possible at the moment. However, based on testing and feedbacks, users said it is effective against 0-days but it just give insight and information and you need to analysis these and take action.
I tryied Defender ATP with SCCM onboarding. Now my trial account Analyst@WindowsATP24xx.onmicrosoft.com is inaccessible. Probably expired. Now I can not do offboarding of all my test client computers. For offboarding I need *.offboard file but I can not access settings on https://securitycenter.windows.com/ Can anyone help me?