In general
Note
Machine translation from the German version. In case of doubt, the content of the German version shall prevail.
Active Directory (AD) is a central directory service from Microsoft used to manage users, computers, and resources within a university network. Active Directory allows user accounts, access rights, group memberships, and security policies to be centrally controlled. Employees log in once with their personal credentials and, depending on their permissions, gain access to required systems, applications, and files. RUB institutions can have their own area within the central Active Directory and benefit from the advantages of Software as a Service. This simplifies administration, enhances security, and enables structured user management. The service is funded by basic financing, so no additional costs are incurred.
Zone concept
The Microsoft tiering model secures Active Directory through a vertical separation of privilege levels: Tier 0 manages the identity infrastructure (domain controllers), Tier 1 handles server applications, and Tier 2 covers endpoint devices. The strict principle prevents high-privilege accounts from logging into less secure systems, mitigating credential theft.

Within Tiers 1 and 2, we are implementing additional "fire protection zones" for horizontal isolation. This administrative segmentation divides systems into separate security zones. Since each zone has exclusive admin accounts, a security incident remains limited to the affected zone, effectively preventing lateral spread of attackers between different institutions of the RUB.
