For security reasons, IIS6 can send 404 when in fact the result should be allowed or denied. Someone trying to gain malicious access will not be warned of the existence of a page on which they can focus.
I can’t remember whether this is the default configuration or whether to enable it.