Hello two :) It's generally a good idea to keep out of the cookie-jar, as it will set of various alarms. It would also be hard to point to the right cookie-jar that you'd need, since not all browsers keep 'em in the same location. You stated that the webapplication runs on an intranet, so I assume you're using Windows Authentication? In that case, consider that each user probably needs to "log on" before they can access their workstations and run applications. Unless the webapplication isn't linked to the Active Directory, and you're keeping a list of users/roles in your database. In that case you can check out the Client Application Services[^]. There's also an article on CodeProject, if memory serves correctly :)
I are troll :)