The server arrives with the system installed and the remote desktop port open — everything else is configured for the task.
The first thing to do is change the password, create a separate administrative account and disable the built-in one. For remote access it is better to use a non-standard port: that cuts out the bulk of automated brute-force attempts.
Install the roles you need through Server Manager. The 2019 edition can install them in the background, but a reboot is mandatory after adding Remote Desktop Services or a domain controller.
Configure the firewall deliberately: one rule per task. A web server will need 80 and 443, a database 1433 — and the latter should not be opened to the outside without an urgent need.
Set a backup schedule and test a restore at least once. A copy that has never been restored does not count as working.