An unmanaged server arrives with the system installed and remote access open. Everything else is your territory, and you set the order of work.
A sensible sequence is usually this: change the credentials, configure the firewall, install updates, and only then the working software.
A system snapshot before installing the main software saves hours. If the configuration turns out badly, rolling back takes a minute instead of reinstalling from scratch.
Monitoring is easy to forget about while everything works. Simple checks on free space and processor load are enough: a disk filled with logs is the most common cause of sudden outages.
If access is lost because of your own firewall rule, there is still the hypervisor-level console — it works bypassing the guest system and lets you put everything right yourself.