IIS 7 general question

What steps need to be taken to password protect an IIS 7 sub-site?   Prompting for login.

I have tried only changing authentication, but is there something else that needs to be done?
For most environments out of the box is secure enough. But with IIS your always running a slight risk, For 99% of users this is good enough though.
