You must assign the new user created (by going to properties) and assigning them to the class group "/Remote Desktop Users".

This is after they are made from going into the control panel as an Administrator and creating their accounts.

You can limit the type of applications / bandwidth / access a user can have via Windows Sever 2008 (Windows 7 has this as well)+ other programs as well. Thing is, most "RDP" providers don't even know how to secure their users from creating havoc.