Many people do not realise just how secure the windows ntlm2 auth actually is. Providing you use a good password and don't have a ton of other ports / exploitable services open then there is no problem having RDP access enabled externally. Many many hosting providers do this already, its no different to enabling SSH access to a linux box really.... Come on, we are not talking telnet here, nor are we talking insecure windows XP machines that are 3 service packs behind anymore.
I myself prefer to close off all but the requires ports for running services and then VPN into the internal networks for management.
I myself prefer to close off all but the requires ports for running services and then VPN into the internal networks for management.