No need to place the BES in the DMZ. Just make sure that the BES can talk OUT on port 3101 TCP and can reach the SRP server closest or in your country.
Click here to look up your SRP server.
https://www.blackberry.com/SRPAddressLookup/index.do
==
To further answer your question on supporting the BES in the DMZ. You are going to have to lock down the Microsoft box pretty tight. Like long complex passwords, locked down or disabling all login accounts except for the BESAdmin account. Turn off all unnecessary services, try not to run IIS if possible. Keep in mind that this box is going to be limited in terms of use and flexibility meaning because it's in the DMZ this box should not have any internal access. This will severely limit your capabilities.
In my environment can manage and maintain all of my servers from my blackberry with 3rd party applications installed on my bb. This is something you will not be able to do with out opening up your dmz to your internal network which is not recommended.