You should keep in mind that individual settings in Boxer might get wiped instead of simply committing the URL-Change, as the old configuration gets removed before the new one gets pushed. Or having endusers to re-enter their AD-Credentials on the device after the change make the helpdesk explode. So you should check the behaviour before.
My initial post describes a good way, to migrate over time by enrolling new users to SEGv2.
For example, you could run the SEGv2 in parallel on a different machine with a different host name (seg2.domain.com), do some testing with a couple of devices and then simply change your external and Split-DNS-Records for the old SEG to the new SEGv2. In that case you woudln`t need to touch any profiles/boxer-configs at all.
Although it sounds quite simple, there are things that might go wrong depending on you individual settings, if clusterig is in place, cert base auth, SMIME, bazillion numbers of users and differen devices/Operating systems.
However, being able to switch back to the classic SEG - just in case things go south - is a good safetynet. Test it (per Device-Type/OS) and migrate users in smaller Chunks. Different devices might behave different.