The JoomlaXTC Administrator Lock plugin adds two new security features to the administrator pages of a Joomla website: URL keyword to Administrator area: Hides the administrator page to unwanted visitors unless they know a private keyword. Authorized visitors must enter the keyword as part of the URL to gain administrator login access, where they can enter their login user and password information, for example: http://yourwebsite.com/administrator?keyword Strict personalized backend component access per user ID: Sometimes it is desirable to grant backend access to certain people and still being able to restrict their access to critical or information-sensitive administration components.

See more here:
Administrator Lock