I think you can use a dedicated PC which has a well known IP address and from that address you need to authenticate by any credentials.
You can set a the proxy to Authentication required and set below the IP addresses that do not require authentication (the PCs used by your users) and the PC not listed here is used by admin. Also you need to set a group policy to grant the admin group unrestricted access and others groups default policy.
The PC used by administrator is always forced to authenticate and so the admin can bypas s the filtering giving his credentials.
I try this by setting an LDAP authentication to an AD server but this works, for me, only in EFW-2.2rc3. The final release 2.2 has a "bug" which I do not know to investigate (see
http://efwsupport.com/index.php?topic=673.0) and the default policy does not work, only unrestricted policy works, so, I think, from that PC you could connect only with admin credentials and not with any other users belonging to another group which has a default policy.