Only allow logins from a specific IP/Range. If my credentials get stolen, the attacker will have to get into our network instead of just logging into the admin portal from anywhere.