Very nicely written tutorial. Good stuff.
Also, may I recommend adding trying the server management software and client management software to further tweak and harden the server connections such as switching switching ciphers, enable certificate based, RADIUS, or domain controller based user...