Security is a complex topic which requires a deep understanding how Desktop, Server, and web applications work.
You need to study all of this and then decide on a strategy. Start with the online help and also read the various
presentations from the UC and Develop Summit meetings.
For example, Server supports a number of different security schemes which may or may not be shared with Desktop.
The product I work on uses enterprise database credentials and we have a custom security provider for Server which
implies that our Desktop and Server products behave the same.
By default, I believe that Server uses a local security store (SqlExpress, I think) which stores (and manages) credentials
in a local database on the server. The way that you manage this is via ArcGIS Server Manager. To contrast, you can
also use Windows credentials and the way that you manage those is view Windows itself. So, how you manage
security depends on which scheme you choose.
I think that you are using Flex Viewer applications so you also have to take that into consideration. I have not
looked at the Flex Viewer but I do recall that some of the other Viewer applications from ESRI do not support all
security schemes supported by ArcGIS Server itself.