Thank you for posting in Microsoft Q&A forum.
Query 1: Yes, you can use the same Azure Services (Web&client apps) which are currently used by CMG Classic. There will be no impact on the existing configuration. You can deploy multiple CMG services from one site into separate subscriptions. The site has a one-to-one relationship with the tenant. You decide which subscriptions to use for various reasons such as billing or logical separation.
Query 2: When the clients are migrated to the new PRI site (e.g. CDE), they will connect with the new CMG VMSS with a new CMG connection point that will be installed at CDE site. You can create a CMG in any available subscription in either tenant. Devices that are joined or hybrid joined to either Microsoft Entra ID could use a CMG. If the user and device identities are in one tenant, but the CMG's subscription is in another tenant, you need to attach the site to both tenants. Technically, the client app isn't needed for the second tenant that only has the CMG service. The client app only provides user and device authentication for clients that use the CMG service.
Query 3: In such a migration situation, the best approach to deal with a new CMG setup is to deploy multiple CMG services from one site into separate subscriptions. The site has a one-to-one relationship with the tenant. You decide which subscriptions to use for various reasons such as billing or logical separation. You can use the same Azure Services (Web&client apps) which are currently used by CMG Classic. There will be no impact on the existing configuration. When the clients are migrated to the new PRI site (e.g. CDE), they will connect with the new CMG VMSS with a new CMG connection point that will be installed at CDE site.
If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Add comment".