In IIS 7, I configured an application called "XYZ" and an application pool for it.
I set the identifier of this application pool to the user, I will call it "Mario".
Mario has NTFS access to the folder / files in which XYZ points to (remote share).
In XYZ authentication settings, only Windows authentication is enabled:

On Windows authentication providers, only NTLM is active:

The physical path credentials for XYZ are set by the application user / pass-through:

, , http://server.com/XYZ, ( ), , , , .
Active Directory , , .
: , , NTFS. . !
Web.config:
