Hello,
If we don't want the Admin Console accessible outside the network will leaving this internal affect this configuration at all?
No, you can only install the Web Interface component in the DMZ. There will be no effect on your internal Adaxes configuration.
How is the Read Only Domain Controller being accessed by Adaxes in the DMZ?
The RODC is required to join the computer where Adaxes Web Interface will be installed to an AD domain. Additionally, it will be used by the Web Interface to obtain service connection points (SCPs) for Adaxes service. Operations will be performed through the Adaxes service installed internally which in its turn will connect to an internal DC.
Would internal users also hit the RODC in the DMZ or would they use the internal DCs?
Adaxes service will not have access to the RODC in the DMZ and thus it will always connect to one of the internal DCs. If you want, you can predefine the DCs to be used by Adaxes as described in the following help article: https://www.adaxes.com/help/?HowDoI.ManageActiveDirectory.ManageDomains.SpecifyDCsForDomain.html.