Ok, I scrapped the radius authentication and went back to NTLM. Is it possible to check for a group membership during/after authentication to allow a user to use SQUID? For instance, I want to be able to take away or grant access to the proxy based on an AD group membership. Thanks Scott