The first connection looks like an ordinary Windows login through the Remote Desktop Connection application. At this stage the machine is clean and ready to be configured.
Go into Server Manager and turn off the Internet Explorer Enhanced Security Configuration — it gets in the way of working with most web interfaces. Check the time zone and regional standards straight away so that times display correctly in logs and databases.
Windows updates are your first line of defence. Run Windows Update manually and wait for the critical patches to install. In parallel, configure the firewall: by default only the RDP port is open, but a web server will need 80 and 443, FTP needs 21 and MS SQL needs 1433. Every open rule should be a deliberate decision.
Make a system backup before installing the main software. In the control panel the snapshot function is available in one click — if something goes wrong during setup, you roll back in a minute instead of reinstalling the OS from scratch.
The next step is creating an additional account with administrator rights and disabling the built-in Administrator. For RDP it is better to use a non-standard port: that cuts out most of the automated scanners trying passwords on port 3389 round the clock.
Once the basics of security are in place, install the roles you need: the IIS web server, certificate services or a file server. Set up monitoring — at least a processor load and free space counter with email alerts. Experience shows that 90% of sudden outages come from a disk filling up with logs.