Whats the authentication process, i read somewhere that IIS maps the entered
info with a NT user account and authenticates if they match. Now is it something
like the active directory where every person who requests is also the user
of the system or otherwise he wont be able to use the system???

Furthermore why do we need double authentication?? first at IIS level and
the second by ASp.NEt itself.

Moreover whats NTLM, Kerberos 5.0, IPSEC security????