But the person being authenticated through Windows will be the very same person authenticating with your app, won't they?
Your very first sentence in this thread was:
So, I, and probably several other people, assumed you knew how to compute a hash.
SQL Server has the built-in Hashbytes...