Yes, it actually works and is fully supported. But, once again, working is not the same as being optimal or providing the best, most complete experience.
As for the unmigrated group policies, this is certainly a journey and not an overnight activity, but the sooner you get started, the sooner you'll be finished.
For legacy apps, use of integrated auth is seamlessly supported without issue or additional configuration on AADJ devices. The overwhelmingly vast majority apps fall into this category and the vast majority of orgs never have any issues with app authentication on AADJ devices.
Don't use the excuse that something is time consuming as a excuse not to do it. The world, and as a result what it takes to support businesses from an IT perspective, has drastically changed over the past five years and not changing with it because it takes time and effort is not a good reason at all. It will take you more time in the long run to try to wedge HAADJ and Autopilot into your existing solutions and process then moving to match our engineering effort and the reality of the modern world and workforce. Additionally, HAADJ will simply never meet the expectations of the modern workforce since that's not what it was ever designed for.