I would have set a security policy which does not allow any kind of inbound admin related traffic from any unknown IP or device
at all, including domestic IPs (and VPNs).
But that's just me, I don't know what the preferences of other dev(sec)ops engineers are.