1. Double check your web filter settings,even without deep ssl scanning you can block https urls. Also enable strict blocking and other advanced options in the web filter profile. You should probably enable safe search for goole, bing, and yahoo.
2. You can use a cloud dns services to help but I would not recommend it as it has been proven to be the main cause for slow internet downloads. We used opendns for a year and now that we have removed it our downloads are (no joke) 10x faster. (http://apcmag.com/why-using-google-dns-opendns-is-a-bad-idea.htm)
3. Enable application control. This will help a lot with proxies sites and proxy software. If they are using a usb application or try to install a proxy software the application control policy will stop it. It will also work for web browsers and other websites/programs other than proxies hulu, netflix, your tube, etc...
4. If you can enable Deep SSL scanning.
5. Another option would be to create two vdoms, enable Explicit Web Proxy in vdom 1 and deny as much traffic as you can and create a web proxy rule. Enable all clients browsers to use the proxy with authentication and then in vdom two create a rule from the web proxy to the internet and apply all profile policies (firewall, av, web filter, application control, DLP, Deep SSL scanning)