Can someone explain why you should use InsightIDR when you have managed Windows Defender ATP in place.
I think it depends on your requirements, your IT environment, and your budget.
Probably best to get in contact with your local Rapid7 team to discuss your options.
I would say that it is due to the fact that they are not the same product. Windows Defender is endpoint protection, InsightIDR is the agent for a SIEM. Same as running it with AMP or Sophos. IDR is not endpoint protection, it is endpoint information and visibility.