Again, seriously off topic for a PHP site/forum but...
Once you've turned Anonymous off and turned NT Auth on in the MMC, then go to the directory in question, open its Properties->Security->Permissions, remove "Everyone" (=Anonymous User) and add the individuals, or better, NT groups, who should have access to the file/directory.
This is scaleable as long as the matrix of content vs. users is either sparse or clustered. Beyond that you'll want to go to an app servers, but it sounds like that isn't a problem, yet.
Another cute trick: index server will obey these permissions also - when you do a query you only get back hits that you have permission for. Hate to say anything nice about MS since they rarely deserve it but this feature is cool.
Yet another cute trick: use an ASP with NT Auth activated (directory or file) to create simple personalized content on the cheap via a DB call keyed by the NT login. You need an accurate DB of nt accounts.
Downside on all of this: you must use IE as browser. NS, et al., won't work.