Hi Jasper,Why not to enable the authentication for all (possibly single sign on), group them into groups and use external acl to separate access rights?
In this case they no one will get authentication popups and blocked sites will be clearly indicated with "Cache access denied message"?
Sorry if I miss something :) Best regards, sich