By default, the only thing you need to do is edit the NTFS permissions of the files you want to protect. Edit the security of the files/folders, and remove the "Anonymous web user" or "Web applications" groups, and the IUSR/IWAM accounts if they have rights. Basically, remove everything except administrators/system. Then, individually add the users/groups from Active Directory that you want to have rights to these web pages.