A clean server system arrives with no roles enabled — that is normal; they are added for the specific task through Server Manager.
Start with security: rename the built-in administrator account, set a long password and restrict the range of addresses allowed to connect over remote desktop.
Add roles one at a time and check the result after each. The web server, certificate services, file server and Remote Desktop Services are configured independently, and this way it is easier to find the source of a problem if something fails to work.
Set up an update schedule through group policy or Windows Update. Critical patches for the server edition are released regularly and should not be postponed for long.
Enable Windows Server Backup and set a snapshot schedule to a separate disk. The built-in tool is enough for the system and files; for databases, configure the dump through the DBMS itself.