If the login pages are on separate ports, the admin and user login pages can be locked down separately, with separate settings and access for each.
And it wouldn't require any splitting on the backend, just restricting users to log in on one port, and admins on another.