Ok, so I realised that my query was wrong so I've updated it to this: external_acl_type internet_domain_group %LOGIN /usr/lib/squid3/ext_ldap_group_acl -R -P -b "dc=domain,dc=com" -D squid@xxxxxxxxxx -W /etc/squid3/ldappass.txt -f "(&(objectclass=person)(sAMAccountName=%u)(memberof=cn=%g,dc=domain,dc=com))" -h srvham09.domain.com Still not working though :-( -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-3-3-8-NTLM-Group-Authentication-tp4668615p4668616.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users