On one of our smaller installations, we changed IIS to require a login before even progressing to the website. In this scenario, we leveraged a Windows user account with restrictions, but this is not scalable.
Additionally, port 17017 can be blocked from the outside world via Windows Firewall - since the only address on the planet that should be talking to it is 127.0.0.1. Then your IIS web proxy or a console web browser can access it.
MailEnable survivor / convert --