Dealing with version upgrades is also something that causes some pain. Istio has a moderately fast release cadence and tracking that and matching Istio versions to the underlying version of K8S on AKS makes for a bit of tedium.
That said, we've been using Istio on AKS for about three years now and for the most part it "just works". Istio itself mostly just hums silently along doing what it does. The pain has usually been more to do with a combination of 3rd party software (like our system for generating and managing the aforementioned TLS certs), corporate policy, and things that are just artifacts of running on Azure and specifics of our architecture.