I beg to differ. You are comparing apples to oranges.
The _security_ of terminal services is quite high. You
can enable 128-bit encryption to ensure that breaking into
your connection is going to be near-impossible.
However, if you want to restict who can connect to what
server, then you are going to need to buy an additional
piece of hardware of software. Microsoft doesn't have a
built-in system for controlling who can connect to what.
However, you can just use strong passwords and a legal
message to discourage people from trying to get into your
server.
Regardless, you could always try using TSVer and a custom
version of the RDP client to restrict who can connect to
your server. I can post more information about this if
you do desire.
The moral of the story is that the system is quite secure
by itself, as long as you follow simple security
procesures.
-M