It's really puzzling where this 'bright' idea came from. How is individually touching tens of thousands of mailboxes to disable EWS (and maintaining this practice for all new mailboxes) is better than disabling at org level and having a few mailboxes allowed to use EWS by overriding at mailbox level.
What is the reasoning behind default should be enabled for all just to have it for a few?
Instead, why not continue to leave the individual setting override the org, and change the default setting for new mailboxes from True to Null ? In this way by default all mailboxes will have it disallowed and only a handful which really need EWS can be explicitly set?
This seems to go completely against best practices ...