http:/ / www.troxo.com/ products/ iispassword/
IISPassword uses Basic HTTP Authentication for password protecting web sites on IIS, just like htaccess works on Apache. That makes your password protected Apache web site compatible with IIS, and vice versa. No longer is there a need for system user accounts and complex access permissions for maintaining a secure, password protected web site. (Authenticated users are not available as CGI variables and you cannot define individual error pages on a per-website basis... but other than that, it's extremely fast and admin/script friendly.)