In that case, rely on IIS security which is fully integrated with Active Directory, not on the separate Node-RED security. It will give far better and more robust protection. Just make sure to set Windows Firewall to disallow any access to port 1880 outside of localhost so that users can only use IIS ports 80/443.