So I don't have any AV on the server right now which works then. I don't really let anyone into the locked IT room let alone log on the server ;-) physical security is always something that seems to get left out with IT security.
MSE - I had looked into it to install on our multipoint/terminal server and it will probably work but there are licensing issues with it potentially. 10 users on just the terminal server and maybe a 10-12 other standalone systems slightly exceeds the 10 systems in a business.
VPN - I'm considering adding
PPTP VPN through the RRAS Role . I'm aware that this can be setup without the SBS running DHCP but I think for the VPN to really work correctly with LAN routing, etc that the SBS needs to control DHCP.