Quick update here for those of you publishing Lync web services with TMG and having trouble with mobile clients:
If you're following the Mobility load balancing requirements you'll find that cookie-based persistence is recommended in order to ensure the clients are always directed to the same Front-End server and session. This isn't an issue for a single FE, but once you start publishing a farm of FEs within TMG you'll notice the Lync mobile clients can't sign in. Android clients can for some reason, but WP7 and iPhone cannot.
The issue you'll face is that while TMG offers you cookie persistence when publishing a web farm, it really only works when the web listener is enabled for forms-based authentication. Since the Lync Web Services cannot be published via FBA the cookie never gets inserted. The end result is that TMG will now round-robin requests between the published farm members and the mobile clients will never sign in due to a ping-pong behavior. You can verify this behavior by draining all Front-End servers from the farm except for one and you'll see the clients can now sign in.
For a small deployment where a single FE can handle your entire user load I recommend switching your TMG persistence to source IP. All requests will hit a single FE, but the mobile clients can now maintain their session. And if an FE fails TMG will then fail over to the next server in the farm automatically. For the folks where multiple FEs are used more for capacity reasons you'll need to use something other than TMG for publishing Lync going forward.