In the web.config for the service, in the Transport element, set the ClientCredentialType to Windows:
<bindings>
<basicHttpBinding>
<binding name="MyBinding">
<security mode="TransportCredentialOnly">
<transport clientCredentialType="Windows" />
</security>
</binding>
</basicHttpBinding>
</bindings>
In your web.config, set the allowed roles and or users:
<system.web>
<authentication mode="Windows"/>
<authorization>
<allow roles=".\Developers"/>
<allow users="DOMAIN\ServiceAccount"/>
<deny users="*"/>
</authorization>
</system.web>
In IIS, your virtual application hosting your WCF service will need to be configured to use Windows Integrated authentication. Be sure to uncheck Anonymous Access.
On the client side, svcutil (or using "Add Service Reference") will generate the corresponding client elements to match that of your service. If using a Windows client, the credentials of the actual user will be passed downstream.