I am looking for specific feedback on WinRM. There are ::still:: debates out there about whether or not making RDP publicly available without a VPN is a good idea–There are no debates on whether or not making SSH publicly available is a good idea, as long as it is setup correctly…

Where does WinRM fit in at this point: Use with a VPN, No VPN, etc?

WinRM is capable of using HTTPS transport, and if your machines are in the domain and have your enterprise certificates on them already, it should Just Work.

