I always use DHCP for WPAD
https://technet.microsoft.com/es-es/library/ee658147.aspx
But this option must always be activated(for static ipaddresses, you use the second option), if it is disabled the users could access any websites
(inetcpl.cpl---lan configuration)
I'm looking at another way to force and is using a list of addresses in your tmg rule
If a user is deactivating the check in ncpa.cpl, they will not be able to navigate