With complex passwords enabled you are already pretty well protected, brute force attacks can still be successful but it would take a huge amount of time and CPU power.
The other main protection is auditing as the guy above said, with management software you can take this a step further and have automated alert notifications when suspicious activity occurs.
We also enable account lock-outs after 3 invalid attempts which makes brute force cracking a lot harder although it does increase the admin overhead.