the problem is after the second authentication at owa the browser seems to drop the accelerator login information... acls are ok... without second login it works fine.
Define 'second login' , if you mean owa access then things are strange. Note that in fact there are 2 different things here, cache authentication versus the owa (webserver) authorization. What happens if you don't use cache authentication ? Also include SQUID version (?) M.