Authentication is a good thing, and it's one of the main reasons why the ISA firewall is a more secure solution than the typical "hardware" firewall . However, like in other areas in life, there can be too much of a good thing.
That's the case with the "Require all users to authenticate" option on the "outbound Web requests listener" (OK, that's hailing back to the ISA 2000 days, but the term is a good one and we should bring it back for ISA 2004/06 and TMG).
Check out Richard Hicks' blog to see what I'm talking about
Thomas W Shinder, M.D., MCSE
Sr. Consultant / Technical Writer