This user uses a laptop so there would be no client for him to remote into.
OK, we are slowly peeling away the onion layers.
So you have SBS, great. You say the user is using Remote Desktop to the Server? This indicates you have given the user admin rights to the server or specifically assigned him log on locally. This is just not necessary.
If you configure RRAS the user's laptop dials in on a VPN and connects to the server. This just gives him an IP Address and does not give him local access to the servers drives. If the user has NTFS permissions to shares then he can map drives to them.
If you know ASP you could engineer a web page that checks the IP address of users and if it is NOT an IP reserved for RRAS then allow them access to a web page that gives them access to the documents they need to access.
Beyond that you should simply not allow any remote access besides OWA or Outlook over HTTP if you feel you can not trust your users.
If you have authorized users to log on locally to your server you need to remove that right ASAP as it gives your users way to much access to your server.
The ToDo list in SBS will setup the RRAS for you if you run through the list.
Also, I assume you are runnign SBS Standard and not Premium.
Last thing, in the future since you are running SBS please post in forum1584.
I hope you find this post helpful.
Regards,
Mark
Check out my scripting solutions at