We have made the changes now and here is the result.
Our setup is like this:
ISE-1 primary admin node, secondary monitor node
ISE-2 secondary admin node, primary monitor node
ISE-3 and ISE-4 policy services nodes
All 4 nodes restarted the ISE application, but not simultaneously.
This is how it worked out:
1. ISE-1 restarted ISE application
2. ISE-2 + one of the PSN:s restarted ISE application
3. The other PSN restarted ISE application
So all roles (admin, monitor and policy) worked all the time, there was minimal or no impact for the users. All the same, after-hours for this kind of change is a good recommendation!
/Peter