Apologies for delayed response on this issue.
We want to stop using on-premise ADFS and use Azure Cloud authentication, in order to do that I understand that I need to manually move my domain from federated to Managed? -- Yes, you are right need to convert domain from federated to managed either use PHS or PTA.
Refer to the below articles, which helps in Migration from ADFS to Pass-Though Authentication or Password Hash Sync Deployment Plan
Deployment plan: Migrating from AD FS to password hash sync: https://aka.ms/ADFSTOPHSDPDownload
Deployment plan: Migrating from AD FS to pass-through authentication: https://aka.ms/ADFSTOPTADPDownload
Once I migrate my domain what changes do I need to do on the application end so they understand that it now needs to use Azure authentication and not ADFS?
To answer this question, we need to understand whether applications which are federated with ADFS support authentication protocols of Azure AD or not. You can leverage Azure AD Application proxy as well, reference: https://learn.microsoft.com/en-us/azure/active-directory/app-proxy/application-proxy
Refer to this white paper Migrating your apps to Azure AD for more detailed information on application migration from ADFS to Azure AD - https://aka.ms/migrateapps/whitepaper
Resources for migrating applications to Azure Active Directory - https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/migration-resources
Above white papers have the rollback options mentioned as well.
Please review this documentation, if you have any questions further let me know would be happy to answer it for you.