{"id":8833,"date":"2026-04-14T10:43:09","date_gmt":"2026-04-14T08:43:09","guid":{"rendered":"https:\/\/www.bayoosoft.com\/?p=8833"},"modified":"2026-04-14T10:43:12","modified_gmt":"2026-04-14T08:43:12","slug":"agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it","status":"publish","type":"post","link":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/","title":{"rendered":"AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-background-position:left center;--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-top:114px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-padding-left-medium:30px;--awb-padding-top-small:0px;--awb-padding-bottom-small:0px;--awb-padding-left-small:30px;--awb-margin-top:0px;--awb-margin-top-small:-30px;--awb-flex-wrap:wrap;\" ><div class=\"awb-background-mask\" style=\"background-image:  url(data:image\/svg+xml;utf8,%3Csvg%20width%3D%221920%22%20height%3D%22954%22%20fill%3D%22none%22%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cg%20clip-path%3D%22url%28%23prefix__clip0_58_109%29%22%20fill%3D%22rgba%2844%2C156%2C140%2C1%29%22%3E%3Cpath%20d%3D%22M1020.86%20519.766c6.47-11.566%2022.45-20.942%2035.71-20.942h375.02c30.93%200%2043.77%2021.877%2028.68%2048.863L1204.02%201006H749l271.86-486.234zM1755.66%20419.989c6.47-11.664%2022.45-21.12%2035.7-21.12h391.65c26.5%200%2037.5%2018.912%2024.57%2042.24L1923%20954h-463.62l296.28-534.011z%22%2F%3E%3Cpath%20d%3D%22M1371.86%20126.941c6.47-11.565%2022.46-20.941%2035.71-20.941h376.02c30.93%200%2043.77%2021.877%2028.68%2048.863L1371%20954H914.98l456.88-827.059z%22%2F%3E%3C%2Fg%3E%3Cdefs%3E%3CclipPath%20id%3D%22prefix__clip0_58_109%22%3E%3Cpath%20fill%3D%22%23fff%22%20d%3D%22M0%200h1920v954H0z%22%2F%3E%3C%2FclipPath%3E%3C%2Fdefs%3E%3C%2Fsvg%3E);opacity: 0.23 ;\"><\/div><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:calc( 1200px + 40px );margin-left: calc(-40px \/ 2 );margin-right: calc(-40px \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-left-small:0px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:20px;--awb-margin-bottom-large:0px;--awb-spacing-left-large:20px;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:20px;--awb-spacing-left-medium:20px;--awb-width-small:100%;--awb-order-small:0;--awb-margin-top-small:100px;--awb-spacing-right-small:20px;--awb-spacing-left-small:0px;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-one\" style=\"--awb-text-color:var(--awb-color2);--awb-margin-top:-50px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h1 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:50;line-height:var(--awb-typography1-line-height);\"><h1>AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it<\/h1><\/h1><\/div><div class=\"fusion-text fusion-text-1\"><p>What is behind Microsoft&#8217;s group structure recommendation, what is the catch and how does the BAYOOSOFT Access Manager solve the problem in a smarter way?<\/p>\n<p>When IT administrators talk about authorization management in Active Directory, sooner or later the abbreviation AGDLP comes up. It is Microsoft&#8217;s official recommendation for structuring groups and access rights in Windows domains, well documented, widely used and, in theory, a decent concept. However, the BAYOOSOFT Access Manager deliberately does not follow this recommendation completely. Not an oversight, not a compromise, but a well-founded technical decision. This article explains what AGDLP is, why the principle reaches its limits in practice and how the BAYOOSOFT Access Manager solves the problem more intelligently.    <\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-padding-bottom-small:0px;--awb-margin-top:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:60px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:3;--awb-margin-top-medium:0px;--awb-spacing-right-medium:0%;--awb-spacing-left-medium:0%;--awb-width-small:100%;--awb-order-small:2;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-margin-bottom-small:0px;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:-20px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>What AGDLP means and why Microsoft recommends it<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-2\" style=\"--awb-text-color:var(--awb-color8);--awb-margin-top:-20px;\"><p>The acronym stands for Accounts (user and computer accounts), Global Groups (global groups), Domain Local Groups (domain-local groups) and Permissions (authorizations) and describes the order in which user accounts and groups should be nested in a Windows domain. The basic principle is role-based: A user account (A) becomes a member of a global group (G) that maps a business role, for example &#8220;Accounting&#8221; or &#8220;Project Management&#8221;. This global role group is then embedded in a domain-local group (DL), which in turn holds specific access rights to a resource, such as read or write access to a network folder. The domain-local group is therefore the only place in the ACL (Access Control List) where authorizations are actually assigned (P).   <\/p>\n<p>The logic behind this is understandable. If an employee changes department, it is sufficient to remove her from the old global group and add her to the new one. All resource accesses follow automatically. Nobody has to touch individual folder ACLs. The model also prevents so-called orphaned SID entries in the ACLs, i.e. remnants of deleted user accounts that otherwise accumulate over the years. When implemented consistently, AGDLP has a positive effect on transparency and Active Directory security.     <\/p>\n<p>Sounds good, and in theory it is. For environments with several domains or overall structures, the G-level is even technically necessary because global groups can be used across domain boundaries and the domain-local resource groups can therefore be filled from any domains. In short: AGDLP solves a multi-domain problem.  <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-left-small:0px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:1;--awb-spacing-right-small:1.92%;--awb-margin-bottom-small:0px;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-3\"><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-right-small:8px;--awb-padding-left-small:10px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:30px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:5;--awb-margin-top-small:25px;--awb-spacing-right-small:0%;--awb-spacing-left-small:0%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-3 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:30px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>The disadvantages of AGDLP: where the principle reaches its limits in practice<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-4\" style=\"--awb-margin-top:-20px;\"><p>The downside of AGDLP is well documented, but still underestimated in many IT teams.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_1_3 1_3 fusion-flex-column fusion-flex-align-self-flex-start\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio: 100 \/ 200;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-1 hover-type-none has-aspect-ratio\" style=\"border-radius:6px;\"><img decoding=\"async\" width=\"1366\" height=\"768\" alt=\"AGDLP Microsofts Best Practice f\u00fcr Active Directory \" title=\"SOFT_AGDLP-Microsofts-Best-Practice-f\u00fcr-Active-Directory_ Absatz1\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1.jpg\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1.jpg\" class=\"lazyload img-responsive wp-image-8835 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%271366%27%20height%3D%27768%27%20viewBox%3D%270%200%201366%20768%27%3E%3Crect%20width%3D%271366%27%20height%3D%27768%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1-200x112.jpg 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1-400x225.jpg 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1-600x337.jpg 600w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1-800x450.jpg 800w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1-1200x675.jpg 1200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz1.jpg 1366w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_2_3 2_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-top-small:20px;--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-5\" style=\"--awb-margin-top-small:-20px;\"><\/div><div class=\"fusion-text fusion-text-6\"><p><b style=\"color: var(--awb-color4)\">1. the initial effort is considerable:<\/b>Each role and each resource requires at least two groups instead of one, the global role group and the domain-local authorization group. This at least doubles the number of groups in Active Directory. The required structures must be set up completely manually in the Active Directory console; there are no standard tools for this. This makes the model labor- and cost-intensive and potentially error-prone at every point where human intervention is required. Anyone who has ever structured an AD with a few hundred folders, printers and applications knows what this means in practice.    <\/p>\n<\/div><div class=\"fusion-text fusion-text-7\"><p><strong style=\"color: var(--awb-color4)\">2. shortcuts undermine the entire model:<\/strong>The model stands and falls with consistent discipline: as soon as someone assigns authorizations directly to a global group &#8220;just this once&#8221;, the structure begins to erode. Before you realize it, the entire AGDLP logic is undermined. The model stands and falls with consistent discipline in every single authorization assignment, over years, by changing teams.  <\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-4 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-margin-bottom:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-8\"><p><b><span style=\"color: var(--awb-color4)\">3. in single-domain operation, the G-level is technically superfluous:<\/span><\/b>Global groups only develop their added value where users from different domains need to be authorized to resources together. If you only operate one domain, AGDLP solves a problem that simply does not exist and still pays the full administrative price. <\/p>\n<\/div><div class=\"fusion-text fusion-text-9\"><p><b style=\"color: var(--awb-color4)\">4. subsequent migrations are extremely time-consuming:<\/b><br \/>Converting existing, historically grown authorization structures to AGDLP means renaming groups, changing types, maintaining old and new groups in parallel, all manually, with a considerable risk of access interruptions.<\/p>\n<\/div><div class=\"fusion-title title fusion-title-4 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:30px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>The token size problem: when users can no longer log in<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-10\" style=\"--awb-margin-top:-20px;\"><p>There is another technical problem that hardly anyone has on their radar in everyday life until it becomes a serious incident: The Kerberos token size.<\/p>\n<p>Each time a user authenticates to the system, Windows issues a Kerberos ticket. This ticket contains not only the user identity, but also the SIDs of all security groups in which the user is a member, directly and indirectly. The formula for this comes directly from the Microsoft documentation:  <\/p>\n<p><strong>TokenSize = 1200 + 40d + 8s<\/strong><\/p>\n<p><span style=\"letter-spacing: 0.24px\">Where d stands for memberships in domain-local groups and universal groups outside your own domain (each: 40 bytes), and s for memberships in global groups and other groups within the domain (each: 8 bytes).<\/span><\/p>\n<p>With the old standard limit of 12,000 bytes (up to Windows Server 2008 R2), membership in more than around 120 universal groups could already lead to authentication errors. On modern systems (from Server 2012), the standard is 48,000 bytes, but the principle remains: The more groups are accumulated through nested AGDLP structures, the closer you get to this limit. If these limits are exceeded, authentication fails and the user can no longer log on. Group policies may no longer be applied. In larger, historically grown environments with deep AGDLP nesting, this is not a theoretical scenario, but a real risk. The maximum value of 65,535 bytes can technically be set, but is expressly not recommended by Microsoft, partly because of known problems with IIS.     <\/p>\n<p>With AGDLP, this problem is structurally reinforced: each global group that is embedded in many domain-local groups accumulates a corresponding number of domain-local group SIDs in the token for each user it contains. The deeper the nesting, the faster the token grows. <\/p>\n<\/div><div class=\"fusion-title title fusion-title-5 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:30px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>How the BAYOOSOFT Access Manager intelligently adapts group structures to the environment<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-11\" style=\"--awb-margin-top:-20px;\"><p>The BAYOOSOFT Access Manager does not follow a single fixed group model, but selects the technically superior structure depending on the environment. The goal is always the same: minimum Kerberos token load with maximum security and compliance. <\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-5 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-right:30px;--awb-padding-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-7 fusion_builder_column_2_3 2_3 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-12\"><p><b style=\"color: var(--awb-color4)\">AGP in single-domain operation<\/b>In single-domain environments, the Access Manager works according to the AGP principle: Accounts are assigned directly to global groups (G), which then hold the authorizations (P). Domain-local groups are completely omitted. As global groups only contribute 8 bytes per membership to the Kerberos token according to the Microsoft formula instead of 40 bytes like domain-local groups, this is the most token-efficient variant of all. There is also a small security advantage: global groups can only include objects from their own domain, which automatically limits the scope to their own environment.   <\/p>\n<\/div><div class=\"fusion-text fusion-text-13\"><div><b style=\"color: var(--awb-color4)\">ADLP in multi-domain operation<\/b><\/div>\n<p>As soon as users or groups from several domains need to access shared resources, domain-local groups come into play because only they allow cross-domain memberships. In this case, the Access Manager works according to ADLP: accounts are assigned directly to domain-local groups (DL), which hold the authorizations (P). The G level from AGDLP is omitted. Each domain-local membership costs 40 bytes in the Kerberos token, so the cost is higher than in single-domain mode. However, this is technically justified and is not further increased by an additional nesting level.    <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-8 fusion_builder_column_1_3 1_3 fusion-flex-column fusion-flex-align-self-center\" style=\"--awb-overflow:hidden;--awb-bg-color:var(--awb-color3);--awb-bg-color-hover:var(--awb-color3);--awb-bg-size:cover;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio: 100 \/ 200;--awb-object-position:41% 48%;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-2 hover-type-none has-aspect-ratio\" style=\"border-radius:6px;\"><img decoding=\"async\" width=\"1366\" height=\"768\" alt=\"AGDLP: Microsofts Best Practice f\u00fcr Active Directory und warum wir bewusst darauf verzichten\" title=\"SOFT_AGDLP-Microsofts-Best-Practice-f\u00fcr-Active-Directory_ Absatz2\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2.jpg\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2.jpg\" class=\"lazyload img-responsive wp-image-8839 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%271366%27%20height%3D%27768%27%20viewBox%3D%270%200%201366%20768%27%3E%3Crect%20width%3D%271366%27%20height%3D%27768%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2-200x112.jpg 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2-400x225.jpg 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2-600x337.jpg 600w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2-800x450.jpg 800w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2-1200x675.jpg 1200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Absatz2.jpg 1366w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-6 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-9 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-padding-top-small:20px;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-14\"><p><strong><span style=\"color: var(--awb-color4)\">Optimized multi-domain mode: ADLP and AGP in parallel<\/span><\/strong>For multi-domain environments with high demands on token efficiency, the Access Manager offers an optimized mode that combines both group types. For each resource, there is both a global and a domain-local group in the ACL, not nested as with AGDLP, but in parallel. Users are then automatically sorted into the group with the most favorable token depending on their domain affiliation: Users from your own domain end up in the global group (8 bytes), users from other domains in the domain-local group (40 bytes). This makes the ACL of an object slightly larger, but each individual user pays exactly the token price that their environment technically requires. No more.    <\/p>\n<p>The following applies in all three modes: The Access Manager creates the required groups fully automatically, maintains memberships and proactively corrects unauthorized changes. The dependency on human discipline for structure maintenance, the core problem of AGDLP, is completely eliminated. <\/p>\n<\/div><div class=\"fusion-title title fusion-title-6 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top:40px;--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>Which group model suits which environment?<\/h2><\/h2><\/div><div class=\"fusion-text fusion-text-15\" style=\"--awb-margin-top:-20px;\"><p>Microsoft&#8217;s AGDLP recommendation is not wrong, it is optimized for a specific context: manual management in multi-domain environments. If you don&#8217;t have this context, you are paying for something that doesn&#8217;t bring you any added value and risk the token size problem on top. <\/p>\n<p>The BAYOOSOFT Access Manager solves this problem not with a single alternative group model, but by intelligently adapting to the respective environment. In single-domain operation, AGP ensures minimal token load and a natural security scope. In multi-domain operation, ADLP provides the necessary cross-domain flexibility. And the optimized multi-domain mode combines both approaches in such a way that every user always ends up in the most favorable token group.   <\/p>\n<p>As a basic requirement (OPS.1.1.1.A2) in IT-Grundschutz, the BSI stipulates that a role and authorization concept must be defined for all IT components in operation. The standard deliberately leaves open which technical group model is to be used. With the BAYOOSOFT Access Manager, this concept can be implemented in a clean and audit-proof manner for file servers, SharePoint, Active Directory and connected third-party systems alike.  <\/p>\n<\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-10 fusion_builder_column_1_1 1_1 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-padding-top:30px;--awb-padding-right:60px;--awb-padding-bottom:30px;--awb-padding-left:61px;--awb-overflow:hidden;--awb-bg-color:var(--awb-color1);--awb-bg-color-hover:var(--awb-color1);--awb-bg-size:cover;--awb-box-shadow:0px 5px 17px 0px rgba(0,0,0,0.4);;--awb-border-radius:6px 6px 6px 6px;--awb-width-large:100%;--awb-margin-top-large:20px;--awb-spacing-right-large:0%;--awb-margin-bottom-large:60px;--awb-spacing-left-large:1.632%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:0%;--awb-spacing-left-medium:1.632%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-builder-row fusion-builder-row-inner fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"--awb-flex-grow:0;--awb-flex-grow-medium:0;--awb-flex-grow-small:0;--awb-flex-shrink:0;--awb-flex-shrink-medium:0;--awb-flex-shrink-small:0;width:104% !important;max-width:104% !important;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-0 fusion_builder_column_inner_2_3 2_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:66.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.88%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.88%;--awb-width-medium:66.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:2.88%;--awb-spacing-left-medium:2.88%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-text fusion-text-16 sm-text-align-center\" style=\"--awb-content-alignment:left;--awb-font-size:18px;--awb-line-height:var(--awb-typography2-line-height);--awb-letter-spacing:var(--awb-typography2-letter-spacing);--awb-text-transform:var(--awb-typography2-text-transform);--awb-text-color:var(--awb-custom_color_1);--awb-text-font-family:var(--awb-typography2-font-family);--awb-text-font-weight:var(--awb-typography2-font-weight);--awb-text-font-style:var(--awb-typography2-font-style);\"><p>This is how we support you<\/p>\n<\/div><div class=\"fusion-text fusion-text-17 fusion-text-no-margin\" style=\"--awb-font-size:17px;--awb-text-color:var(--awb-color8);--awb-margin-bottom:25px;\"><p>Your solution around file servers, SharePoint, Active Directory and third-party systems \u2013 From standardizing user and access management to supporting the supply of IT services: Optimize entire process chains with BAYOOSOFT Access Manager and sustainably reduce operational efforts while increasing information security.<\/p>\n<\/div><div ><a class=\"fusion-button button-flat fusion-button-default-size button-custom fusion-button-default button-1 fusion-button-default-span fusion-button-default-type\" style=\"--button_accent_color:var(--awb-color1);--button_accent_hover_color:var(--awb-color1);--button_border_hover_color:var(--awb-color7);--button_border_width-top:1px;--button_border_width-right:1px;--button_border_width-bottom:1px;--button_border_width-left:1px;--button_gradient_top_color:var(--awb-color3);--button_gradient_bottom_color:var(--awb-color3);--button_gradient_top_color_hover:var(--awb-color7);--button_gradient_bottom_color_hover:var(--awb-color7);\" target=\"_self\" href=\"https:\/\/www.bayoosoft.com\/en\/product\/bayoosoft-access-manager\/\"><span class=\"fusion-button-text awb-button__text awb-button__text--default\">Learn more<\/span><\/a><\/div><\/div><\/div><div class=\"fusion-layout-column fusion_builder_column_inner fusion-builder-nested-column-1 fusion_builder_column_inner_1_3 1_3 fusion-flex-column fusion-flex-align-self-stretch\" style=\"--awb-bg-size:cover;--awb-width-large:33.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:5.76%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:5.76%;--awb-width-medium:33.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:5.76%;--awb-spacing-left-medium:5.76%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-center fusion-content-layout-column\"><div class=\"fusion-image-element \" style=\"--awb-aspect-ratio:1 \/ 1;--awb-caption-title-font-family:var(--h2_typography-font-family);--awb-caption-title-font-weight:var(--h2_typography-font-weight);--awb-caption-title-font-style:var(--h2_typography-font-style);--awb-caption-title-size:var(--h2_typography-font-size);--awb-caption-title-transform:var(--h2_typography-text-transform);--awb-caption-title-line-height:var(--h2_typography-line-height);--awb-caption-title-letter-spacing:var(--h2_typography-letter-spacing);\"><span class=\" fusion-imageframe imageframe-none imageframe-3 hover-type-none has-aspect-ratio\"><img decoding=\"async\" width=\"300\" height=\"300\" title=\"BAYOOSOFT Access Manager\" src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager.png\" data-orig-src=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-300x300.png\" class=\"lazyload img-responsive wp-image-1226 img-with-aspect-ratio\" data-parent-fit=\"cover\" data-parent-container=\".fusion-image-element\" alt srcset=\"data:image\/svg+xml,%3Csvg%20xmlns%3D%27http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%27%20width%3D%27512%27%20height%3D%27512%27%20viewBox%3D%270%200%20512%20512%27%3E%3Crect%20width%3D%27512%27%20height%3D%27512%27%20fill-opacity%3D%220%22%2F%3E%3C%2Fsvg%3E\" data-srcset=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-200x200.png 200w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager-400x400.png 400w, https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2024\/02\/AccessManager.png 512w\" data-sizes=\"auto\" data-orig-sizes=\"(max-width: 640px) 100vw, 400px\" \/><\/span><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-7 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-padding-left:0px;--awb-flex-wrap:wrap;--awb-box-shadow: 0px 0px var(--awb-color8);\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1248px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-11 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-title title fusion-title-7 fusion-sep-none fusion-title-text fusion-title-size-two\" style=\"--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;\"><h2 class=\"fusion-title-heading title-heading-left fusion-responsive-typography-calculated\" style=\"margin:0;--fontSize:30;line-height:1.16;\"><h2>FAQ: Frequently asked questions about AGDLP, group models and authorization management in Active Directory<\/h2><\/h2><\/div><div class=\"accordian fusion-accordian\" style=\"--awb-border-size:1px;--awb-icon-size:25px;--awb-content-font-size:var(--awb-typography4-font-size);--awb-icon-alignment:left;--awb-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-border-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-background-color:var(--awb-color1);--awb-divider-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-divider-hover-color:hsla(var(--awb-color5-h),var(--awb-color5-s),var(--awb-color5-l),calc( var(--awb-color5-a) - 97% ));--awb-icon-color:var(--awb-color5);--awb-title-color:var(--awb-color7);--awb-content-color:var(--awb-color8);--awb-icon-box-color:var(--awb-color7);--awb-toggle-hover-accent-color:var(--awb-color5);--awb-title-font-family:var(--awb-typography1-font-family);--awb-title-font-weight:var(--awb-typography1-font-weight);--awb-title-font-style:var(--awb-typography1-font-style);--awb-content-font-family:var(--awb-typography4-font-family);--awb-content-font-weight:var(--awb-typography4-font-weight);--awb-content-font-style:var(--awb-typography4-font-style);\"><div class=\"panel-group fusion-toggle-icon-unboxed\" id=\"accordion-8833-1\"><div class=\"fusion-panel panel-default panel-0f96d6dd91d3c612d fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_0f96d6dd91d3c612d\"><a aria-expanded=\"false\" aria-controls=\"0f96d6dd91d3c612d\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#0f96d6dd91d3c612d\" href=\"#0f96d6dd91d3c612d\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What is AGDLP?<\/span><\/a><\/h4><\/div><div id=\"0f96d6dd91d3c612d\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_0f96d6dd91d3c612d\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>AGDLP stands for Accounts, Global Groups, Domain Local Groups, Permissions and describes Microsoft&#8217;s recommended method for role-based authorization management in Active Directory. User accounts are assigned to global role groups, which in turn are embedded in domain-local authorization groups. These then hold the actual access rights to resources such as network folders or printers.  <\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-489fbca555801adf9 fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_489fbca555801adf9\"><a aria-expanded=\"false\" aria-controls=\"489fbca555801adf9\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#489fbca555801adf9\" href=\"#489fbca555801adf9\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">Why does Microsoft recommend AGDLP?<\/span><\/a><\/h4><\/div><div id=\"489fbca555801adf9\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_489fbca555801adf9\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Microsoft developed AGDLP primarily for multi-domain and multi-forest environments. Global groups can be used across domains, whereas domain-local groups cannot. The G-level makes it possible to bundle users from different domains via a uniform role group and jointly authorize them to access resources. In single-domain environments without this requirement, the technical added value is significantly lower.   <\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-d863025c1fe327168 fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_d863025c1fe327168\"><a aria-expanded=\"false\" aria-controls=\"d863025c1fe327168\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#d863025c1fe327168\" href=\"#d863025c1fe327168\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">What is the Kerberos token size problem with AGDLP?<\/span><\/a><\/h4><\/div><div id=\"d863025c1fe327168\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_d863025c1fe327168\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>At logon, Windows creates a Kerberos ticket that contains the SIDs of all the user&#8217;s security groups. According to the Microsoft formula, domain-local groups take up five times as much space as global groups (40 vs. 8 bytes). Deeply nested AGDLP structures therefore increase the token size considerably. If the token exceeds the limit, authentication fails and users can no longer log in.   <\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-256b52d144748110f fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_256b52d144748110f\"><a aria-expanded=\"false\" aria-controls=\"256b52d144748110f\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#256b52d144748110f\" href=\"#256b52d144748110f\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">How does the BAYOOSOFT Access Manager deal with the token size problem?<\/span><\/a><\/h4><\/div><div id=\"256b52d144748110f\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_256b52d144748110f\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>The Access Manager intelligently adapts the group model to the respective environment. In single-domain operation, it uses AGP with global groups (8 bytes per membership). In multi-domain mode, it uses ADLP with domain-local groups (40 bytes). In optimized multi-domain mode, both group types exist in parallel in the ACL, and each user is automatically sorted into the group with the most favorable token. This keeps the Kerberos token load as low as technically possible.    <\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-4187d2bfa5abe95f0 fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_4187d2bfa5abe95f0\"><a aria-expanded=\"false\" aria-controls=\"4187d2bfa5abe95f0\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#4187d2bfa5abe95f0\" href=\"#4187d2bfa5abe95f0\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">  Is the Access Manager's approach secure and compliant?<\/span><\/a><\/h4><\/div><div id=\"4187d2bfa5abe95f0\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_4187d2bfa5abe95f0\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>Yes, all three group models implement the same RBAC principle and fully meet the requirements of IT baseline protection, ISO 27001 and GDPR. The decisive factor is not the specific group model, but that authorizations are assigned in a role-based, traceable and audit-proof manner. The BAYOOSOFT Access Manager ensures exactly that, with automatic documentation of all authorization changes and proactive auto-correction in the event of deviations.   <\/p>\n<\/div><\/div><\/div><div class=\"fusion-panel panel-default panel-83171c7fb29712e9f fusion-toggle-has-divider\"><div class=\"panel-heading\"><h4 class=\"panel-title toggle\" id=\"toggle_83171c7fb29712e9f\"><a aria-expanded=\"false\" aria-controls=\"83171c7fb29712e9f\" role=\"button\" data-toggle=\"collapse\" data-parent=\"#accordion-8833-1\" data-target=\"#83171c7fb29712e9f\" href=\"#83171c7fb29712e9f\"><span class=\"fusion-toggle-icon-wrapper\" aria-hidden=\"true\"><i class=\"fa-fusion-box active-icon fa-angle-down fas\" aria-hidden=\"true\"><\/i><i class=\"fa-fusion-box inactive-icon fa-angle-right fas\" aria-hidden=\"true\"><\/i><\/span><span class=\"fusion-toggle-heading\">For whom is AGDLP useful, for whom not?<\/span><\/a><\/h4><\/div><div id=\"83171c7fb29712e9f\" class=\"panel-collapse collapse \" aria-labelledby=\"toggle_83171c7fb29712e9f\"><div class=\"panel-body toggle-content fusion-clearfix\">\n<p>AGDLP is useful in manually managed multi-domain environments where users from different domains need to access resources together. In automated IAM environments, rigid AGDLP nesting is not necessary. Instead, the BAYOOSOFT Access Manager selects the appropriate model depending on the environment, thus minimizing token load and administrative effort at the same time.  <\/p>\n<\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":40,"featured_media":8843,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45,47],"tags":[234,233,182,230,203],"job-standort":[],"job-bereich":[],"job-arbeitszeit":[],"job-gmbh":[],"class_list":["post-8833","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bayoosoft-access-manager-en","category-posts","tag-active-directory","tag-agdlp","tag-am","tag-bayoosoft-access-manager","tag-best-practice"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.6 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>AGDLP: Microsoft Best Practice for Active Directory<\/title>\n<meta name=\"description\" content=\"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AGDLP: Microsoft&#039;s best practice for Active Directory and why we deliberately do without it\" \/>\n<meta property=\"og:description\" content=\"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/\" \/>\n<meta property=\"og:site_name\" content=\"BAYOOSOFT\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-14T08:43:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-14T08:43:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1366\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"benjaminossowski\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"benjaminossowski\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"48 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/\"},\"author\":{\"name\":\"benjaminossowski\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/1874a19c5cb71ac6d1e56017a9d4c802\"},\"headline\":\"AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it\",\"datePublished\":\"2026-04-14T08:43:09+00:00\",\"dateModified\":\"2026-04-14T08:43:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/\"},\"wordCount\":9675,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/04\\\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg\",\"keywords\":[\"Active Directory\",\"AGDLP\",\"AM\",\"BAYOOSOFT Access Manager\",\"Best Practice\"],\"articleSection\":[\"BAYOOSOFT Access Manager\",\"Posts\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/\",\"name\":\"AGDLP: Microsoft Best Practice for Active Directory\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/04\\\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg\",\"datePublished\":\"2026-04-14T08:43:09+00:00\",\"dateModified\":\"2026-04-14T08:43:12+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/1874a19c5cb71ac6d1e56017a9d4c802\"},\"description\":\"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/04\\\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg\",\"contentUrl\":\"https:\\\/\\\/www.bayoosoft.com\\\/wp-content\\\/uploads\\\/sites\\\/5\\\/2026\\\/04\\\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg\",\"width\":1366,\"height\":768,\"caption\":\"AGDLP: Microsofts Best Practice f\u00fcr Active Directory und warum wir bewusst darauf verzichten\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\\\/bayoosoft-access-manager-en\\\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/www.bayoosoft.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#website\",\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/\",\"name\":\"BAYOOSOFT\",\"description\":\"L\u00f6sungen im Bereich IT-Security und Medical Solutions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.bayoosoft.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.bayoosoft.com\\\/#\\\/schema\\\/person\\\/1874a19c5cb71ac6d1e56017a9d4c802\",\"name\":\"benjaminossowski\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g\",\"caption\":\"benjaminossowski\"},\"url\":\"https:\\\/\\\/www.bayoosoft.com\\\/en\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"AGDLP: Microsoft Best Practice for Active Directory","description":"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/","og_locale":"en_US","og_type":"article","og_title":"AGDLP: Microsoft's best practice for Active Directory and why we deliberately do without it","og_description":"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.","og_url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/","og_site_name":"BAYOOSOFT","article_published_time":"2026-04-14T08:43:09+00:00","article_modified_time":"2026-04-14T08:43:12+00:00","og_image":[{"width":1366,"height":768,"url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg","type":"image\/jpeg"}],"author":"benjaminossowski","twitter_card":"summary_large_image","twitter_misc":{"Written by":"benjaminossowski","Est. reading time":"48 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#article","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/"},"author":{"name":"benjaminossowski","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/1874a19c5cb71ac6d1e56017a9d4c802"},"headline":"AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it","datePublished":"2026-04-14T08:43:09+00:00","dateModified":"2026-04-14T08:43:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/"},"wordCount":9675,"commentCount":0,"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg","keywords":["Active Directory","AGDLP","AM","BAYOOSOFT Access Manager","Best Practice"],"articleSection":["BAYOOSOFT Access Manager","Posts"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/","url":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/","name":"AGDLP: Microsoft Best Practice for Active Directory","isPartOf":{"@id":"https:\/\/www.bayoosoft.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#primaryimage"},"image":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg","datePublished":"2026-04-14T08:43:09+00:00","dateModified":"2026-04-14T08:43:12+00:00","author":{"@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/1874a19c5cb71ac6d1e56017a9d4c802"},"description":"AGDLP in Active Directory explained: limits, challenges and how the BAYOOSOFT Access Manager manages authorizations smarter.","breadcrumb":{"@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#primaryimage","url":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg","contentUrl":"https:\/\/www.bayoosoft.com\/wp-content\/uploads\/sites\/5\/2026\/04\/SOFT_AGDLP-Microsofts-Best-Practice-fuer-Active-Directory_-Header.jpg","width":1366,"height":768,"caption":"AGDLP: Microsofts Best Practice f\u00fcr Active Directory und warum wir bewusst darauf verzichten"},{"@type":"BreadcrumbList","@id":"https:\/\/www.bayoosoft.com\/en\/bayoosoft-access-manager-en\/agdlp-microsofts-best-practice-for-active-directory-and-why-we-deliberately-do-without-it\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/www.bayoosoft.com\/"},{"@type":"ListItem","position":2,"name":"AGDLP: Microsoft&#8217;s best practice for Active Directory and why we deliberately do without it"}]},{"@type":"WebSite","@id":"https:\/\/www.bayoosoft.com\/#website","url":"https:\/\/www.bayoosoft.com\/","name":"BAYOOSOFT","description":"L\u00f6sungen im Bereich IT-Security und Medical Solutions","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bayoosoft.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.bayoosoft.com\/#\/schema\/person\/1874a19c5cb71ac6d1e56017a9d4c802","name":"benjaminossowski","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9bd76799e4792e39c257fca3ef895c5d35641fe9bb0f56016853b335b865f58e?s=96&d=mm&r=g","caption":"benjaminossowski"},"url":"https:\/\/www.bayoosoft.com\/en"}]}},"_links":{"self":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8833","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/comments?post=8833"}],"version-history":[{"count":3,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8833\/revisions"}],"predecessor-version":[{"id":8890,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/posts\/8833\/revisions\/8890"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media\/8843"}],"wp:attachment":[{"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/media?parent=8833"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/categories?post=8833"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/tags?post=8833"},{"taxonomy":"job-standort","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-standort?post=8833"},{"taxonomy":"job-bereich","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-bereich?post=8833"},{"taxonomy":"job-arbeitszeit","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-arbeitszeit?post=8833"},{"taxonomy":"job-gmbh","embeddable":true,"href":"https:\/\/www.bayoosoft.com\/en\/wp-json\/wp\/v2\/job-gmbh?post=8833"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}