While I have been very impressed with the enhancements in managing ActiveSync devices in SP1, one thing I was particularly disappointed in is that it appears you only have the ability to create device access rules based on only the 'Device family' and the 'Model.' It would be extremely valuable to Exchange Admins in a corporate environment to be able to use other ActiveSync data that is collected to more granularly control device access such as 'DeviceUserAgent' and 'DeviceOS.' This would allow for the ability to allow/disallow not only particular devices and models but devices with OS versions that you may not have yet tested or don't support features required in your environment.