It's my understanding that it can be removed from domain admins - but not sysadmins.
A better option would be the ability to disable symmetric encryption altogether on user passwords and use an one-way system instead. This would be more code to implement and there would be implications for making changes to a live system.
MailEnable survivor / convert --