We use the NAT IPs feature mainly for 'allow-only' policies.
It would be very useful especially when first implementing a new policy to view and report on DNS activity by policy. This would assist us in troubleshooting problems and also verify the policy is performing as expected and allow URLs needed for say OS updates or endpoint protection clients.