I have just started work for a small (100-150 employees) company. I noticed that anybody can remote in to the remote server using the correct domain, which is quite easy to guess based on the company name and the name of the server.
Seen as RDP is not behind a firewall or VPN and therefore accessible to anybody who a) knows the address and b) knows a user account - is it a big security risk?
I believe RDP has some in-built protection against brute force attacks, is there any other way somebody could gain unauthorized access?
Should I push to have RDP only accessible via VPN?
Thank you.