In order to get mobile email syncing to work in our Exchange 2010 / Server 2008R2 we have to go to the users account in AD, go to properties, security, advanced and select the top object which is an Exchange Servers permission with 'create msExchActiveSyncDevices o...' and the delete version of that in it.
Then on that object we tick 'include inheritable permissions from this objects parent'.
I will admit I don't have enough background knowledge of how this works, but we're experiencing an issue where this gets unticked randomly for some users, and they are then unable to sync their email.
Does this get revoked somehow if the user does something? Or does anyone know anything else about why it would be unticking itself? We have the latest updates installed for Exchange and Windows