Prevent unauthorized Grav admin login attempts?

Using .htaccess to restrict brute force bot login attempts via the admin plugin - by whitelisting IP numbers or protecting the admin folder with a password? Would doing so break anything?