Is there any way to configure Windows 7 RDP to require a client certificate to login

You need to set up domain and server isolation in order to use certificates to encrypt traffic using IPSEC. All traffic is encypted by default at the highest level supported by the client (unless you have configured it not to fall back to older encryption methods) so if you are looking to just encrypt you don't need to change anything.