It can analyze an attackers moves within your network, figuring out what files they accessed, ways they pivoted, and other stuff. So not only would it detect that you got compromised, but the display will show you likely paths, names of users that are also compromised, mitigation steps, deployed persistence measures, etc.
So for Defender ATP to work optimally in a deployment that leverages linux nodes, or has users using linux as their daily driver, you need to support linux.