You can configure a local policy to avoid the denied sites. For example, the following policy keeps IEonline.Microsoft.com, download.Microsoft.com and Download.windowsupdate.com from being added to the access log,
<proxy>
url.domain=ieonline.microsoft.com access_log(no)
url.domain=download.microsoft.com access_log(no)
url.domain=download.windowsupdate.com access_log(no)