Thank you for posting this in Microsoft Q&A.
As I understand you want to know the impact on user's if you set up hybrid Entra join for user devices.
Since you already have hybrid environment it means that users are already synced to Entra ID and they are currently accessing there Entra resources.
If you do a device hybrid Entra ID join, there is no impact on users. User's will be able to utilize the Single Sign-on capability.
Apart from that as per your requirement, you will be able to configure conditional access policies devices.
If the device failed to Hybrid Entra ID join, then users will still be able to login to the device because while logging in to device users will use there on-premises credentials.
Only single sign-on will fail for Entra ID resources. Or if you have set up any conditional access policy for any Entra resource, then even that will fail.
Apart from this there is no other impact if Hybrid Entra ID join fails.
Let me know if you have any further questions.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.