Of course you can do that and a firewall to protect all other ports will go
a long way to protect the computer. Be sure to do other normal securing
procedures such as requiring the use of complex passwords, having an account
lockout policy with a lockout threshold of no less than ten and a reset
interval of around ten minutes to deter brut force password attacks, using
antivirus, disabling unneeded services, and keeping current with critical
updates. Since the built in administrator account can not be locked out and
is the top target of attacks I would disable that account from logon through
TS in it's account properties.
It would increase security quite a bit if you could configure the firewall
to only accept inbound port 3389 from authorized IP addresses of your users.
That may not be possible if they roam or do not have static IP addresses.
Also using a VPN to access the TS would increase security particularly if
you can use l2tp that would require computer certificates for authentication
to logon to the VPN. Users could then logon to the VPN and then access the
TS via it's LAN IP address and it would not have to be exposed to the
internet. --- Steve