Thanks Jade. I found the kernel parameter in the antispam section where I can list allowed tags. I was just wondering if there was an all_html flag somewhere.
Our users are used to copying and pasting the html source of sites under scrunity. I need to preserve this functionality.
This intranet holds some very private and low level classified information thus there is no connection between the internet and the intranet. In order to pull off a cross site attack the attacker would have to first break the virtual machine isolation.
Thanks Joel - you posted while I was typing.