What this script does:
- Find all ActiveSync enabled mailboxes. I use an AD Directory Searcher method, so reading the values on 100,000 mailboxes only takes a few minutes, not hours.
- Reads an "Exchange ActiveSync Opt-in" group, containing groups and/or mailboxes.
- Disables all mailboxes not in the Opt-In group. Enable all mailboxes in Opt-In group.
- Look at nested groups in Exchange ActiveSync Opt-in, compare names to ActiveSync Mailbox Policies in Organization, if matches, apply policy to all mailboxes in group.