A custom map with a few or just one user was selected. Active Directory Processing Wizard ran and, according to the log file, processed permissions on many objects such as resource mailboxes even though the users in the custom map did not have any permissions on these resource mailboxes.
This can happen if some resource mailboxes msexchmasteraccountsid attribute set to well known SELF sid, but no associated external account entry in mailbox security descriptor. ADPW corrects this by modifying msexchmailboxsecuritydescriptor.
This behaviour is by design, even when custom map is selected, permissions given to SELF sid will still be modified where necessary.