Hi, I am currently using SquidNT (Version 2.6.STABLE13) as a local proxy in each of our smaller offices. I authenticate against MS Active Directory using a Global Group. I have noticed that the authentication has a limitation in that the helper seems not to check Group membership recursively, i.e. it will only look at the first result and if that result is a group, it will not check membership of the lower group. I have learned to live with this but changes in our AD policy will require me to make my internet access group a member of a higher group and I should then authenticate to the higher group, that will no work (I hope I'm making sense). I have treid this with 3.0.STABLE13-BZR and it persists. Any way to work around this? Thanks in advance. Jacques Kruger