Another big issue is dealing with email-enabled security group management, for example organisations which uses the same group as distribution list and granting application or file shares access using the same group will never be able to rely on EXO management, unfortunately even after reaching out to Microsoft team to find a proper solution for this scenario, LES won't work in this case.
I have evaluated Tim McMichael solution to automate the creation of the same group to exchange online and rename the on premise group and remove the email address so we end up with 2 groups, on premises as just security group where the SID maintained the same so the assigned permissions won't be impacted and then the distribution list will be running from EXO., but with +15000 existing groups in scope it won't be practial for managing and maintaining +30000 after splitting the groups and link the permissions manually twice when any membership requires modification for each group.
Below is a reference for the great tool which Tim has worked on
https://timmcmic.wordpress.com/2023/02/21/office-365-distribution-list-migrations-2-0-part-33/