An EAW server running on SQL could be password protected by adding the password to the campaigninfo table. I'm not sure if the db structure for SFC3 is similar or not, but if you are running on SQL take a look for the password field in the campaigninfo table. I'm not sure if the field is present in the flatfile or how to add it. If all that is too much, Corbo's suggestion is the simplest, just put a unique file (rules text?) in the validatedclientfiles folder and rename it to an .scr file then distribute it to those who you want to allow in.