Yes. I started a thread last month to try to get people to make comments on setting up Profiles when using Active Directory SSO (
http://www.astaro.org/astaro-gateway...-profiles.html). In that, I proposed that the base profile should be in transparent mode and have the most-stringent blocking compared to the Profiles. No one contested that, but no one specifically "blessed" that approach either.
In your case, I would think you would want a complete block and transparent mode for the base HTTP Proxy configuration, thus forcing people to correct their browser settings. The advantage of that is that you can customize the blocking message to give a link to instructions on making the browser settings. Then again, if you get rid of ANY transparent access AND you don't open port 80, you achieve a similar result, though without an immediate prompt for self-help.
In any case, it sounds like you have some good experience, so I would appreciate you adding your thoughts to the thread after you resolve your issue.
Cheers - Bob