I would have set a security policy which does not allow any kind of inbound admin related traffic from any unknown IP or device at all, including domestic IPs (and VPNs).

But that's just me, I don't know what the preferences of other dev(sec)ops engineers are.