This should have been posted at but since you're here I'll try to answer.

It sounds like your login script isn't very robust. I'm picking that it just redirects to a page which includes the video link. Ideally you need the video to be in a protected directory so any files within that directory can only be accessed with the correct login details.

I don't use Windows servers (I use Linux) so I can't comment on using Windows Authentication.

When you say that people can access the file without logging in, how do they do this? How do they get to the page with the link?

The best thing you could do is show me the URL so I can see for myself.
