Hey, I have a lot of anonymous users showing up in my Webproxy logs for ISA. I was wondering why they are there. I do have "Ask unauthenticated users for identification" check for both incoming and outgoing web request. Another part of this puzzle is at the same time a web call is being made from the same computer to the same site. The different about this call is that it has the user name. Here is example of the log. anonymous wisapidata.weatherbug.com 10.1.3.122 4167 299 00:05:50 05/04/03 anonymous wisapidata.weatherbug.com 10.1.3.122 803 0 00:05:50 05/04/03 USOCE\diazk wisapidata.weatherbug.com 10.1.3.122 138 523 00:05:50 05/04/03 Does spyware type applications make a web call under anonymous and still get out even with "Ask unauthenticated users for identification" checked off. I'm toying with the idea of blocking some sites and things like that, but thats a policatal battle. Thanks and have a nice day. Dan