Think about this too: If your app doesn't even use session variables or cookies, there's no need for application.cfm
I'm really interested in learning more about <CFAUTHENTICATE>, IsAuthenticated(), and AuthenticatedUser(). I think these are the way to go, but don't quite know how to use them. Can somebody tell me how to take usernames and passwords from a SQL7 DB and put them in "User Directories" in CF Server Advanced Security? Any help would be greatly appreciated.