Are you referring to the authentication that enabled in WSA that the WSA connected to the AD server that has child domain (domain1.domain.com) and you will be migrating the AD to to parent domain?
If this understanding is correct, you can do so in the authentication realm to put the AD server that you want the WSA to connect to. The 2 AD servers (parent and child domain), and if you want WSA to know the users under those domains, you will need to have those domains to have 2 way trust to each other as pre-requisite.
So eventhough the WSA only joining to the parent domain AD server and since that AD server has 2 way trust to the child domain, therefore WSA still be able to see the users and groups on the child domain.
Hope this helps.