Why do you shut off the Remote Desktop? Those virtual images are made to run headless so it's a good option to have running depending on your application.
Never ever had a customers machine compromised with Remote Desktop enabled, they were always behind a firewall with strict rules or through a VPN. A quick port change on RD keeps the script kiddies away too.
There was talk one time of a port knocking gateway, where you could ping a specific number of ports in a specific order and that would open up the ports for remote access. Never did get around to trying it out though.
I don't need it for anything, I don't really trust that there isn't someone at MS that could tap into these "free" machines so I shut it off, just me LoL.