I presume it is possible with the Firewall Client you are able to set up NT Groups in the following way: ISA_IRC ISA_ICQ ISA_WindowsUpdate ISA_Messenger ISA_Telnet ISA_SSH and so on... And only put the people you allow into each on of those groups? Also... I am also it is possible to assign multiple application protocols to a group like ISA_ISSTAFF to include protocol you don't want normal users to be able to access? _______________________________________________________ Skeeve Stevens Email: skeeve@xxxxxxxxxx Website: www.skeeve.org - Telephone: (0414) 753 383 Address: P.O Box 1035, Epping, NSW, 1710, Australia _______________________________________________________ Avis est! Aeronavis est! supervir est!