We do something similar @ our small company. The remote user logs into the VPN (that program is furnished as a feature of the hardware firewall) and then using RDP, into their desktop. Their desktop login only allows them to see what they normally see when they are in the office.

The only weakness that I have heartburn over is that the remote Windows PC can memorize the RDP password (which is their desktop PW.) As part of the conditions of remote privileges, remote users are not to use that feature.