If I was to decommission the existing CA but without revoking the issued certs, would the machines on the domain still trust the issued certs that were issued from that CA?
they will if you issue a long-valid CRL. Ideally, CRL validity should match or be greater than CA certificate expiration time. In this case, clients will be ok in using their CA even if it is already decommissioned.