We're running IIS7 on a Windows 2008 server, and I have a .NET web application that is running under a separate application pool. For the moment the application is setup using Basic Authentication. All users to the site have an account created in active directory, which resides on a separate server...