If you concerned that anyone along the datapath between your users and your server might capture the PPTP traffic, and recover from the traffic your users passwords, then you should disable PPTP. Usually it will only be ISPs along the path who are able to do that.