A friend of mine, Peter Kellner, has a couple of articles online:
If you're working with ASP.NET 2.0 role-based security, give them a read!
Disclaimer The opinions expressed herein are my own personal opinions and do not represent my employer's view in any way.