Best practice for securing the Umbraco back office

Given that you can normally guess its default urI, is there any recommended way of securing the Umbraco back office? changing the login url, restricting back office login to certain ip addresses, running under https etc


This is a companion discussion topic for the original entry at https://our.umbraco.com/forum/72594-best-practice-for-securing-the-umbraco-back-office