Administrative pages are high-value targets for attackers and require stronger authentication than standard username/password. Basic auth and single-factor passwords are vulnerable to compromise. Multi-factor authentication (2/3 factors) provides defense-in-depth by requiring something you know plus something you have or are. No lockout would actually increase vulnerability.