If you are trying to defend against RDP types of attacks I think the best thing to do as a basic step is to change the RDP port number to something different.
Another basic step would be to make a new Admin account (with a name that is not anything like Admin and set a 14+ charter password on it) and change the old Admin account to Guest permissions or disable it.
My 2 cents

Brian
It sounds like they are trying to attack one system ("that system") so moving the RDP port (not a bad idea) would only stop the laziest of attackers who never ran nmap.
I usually rename the admin account, but Brian's idea is a little better since the admin SSID is not 500.
I would suggest trying a quick null session enumeration with
enum. It should give you lots of juicy info.