In the IIS administration panel, you need to find the website or virtual host that your father's site runs under.
Within the directory security tab you can set it to not use the default anonymous login which uses the built-in IUSR_machinename login.
For basic passwording, set it to use plain text. MS authentication will mean that they need to be on the same domain as the server and given rights to it.
If the page is part of a larger site, it would be best to create a virual host under the main site's structure and have it point to a separate directory that holds the pages he wants protecting.
Then do the above changes to that v-hosts directory security tab.
|