My $0.02 -- I generally don't recommend Standby Master deployments. IME, the fail-back from Standby to the original Master has a bad habit of botching configuration changes made during the outage.
I use VRRP, and HA groups, and tailor the ADP scenario to survive loss of the Master, then tell the admin staff "if your Master controller falls off the planet, you can't make config changes until you promote one of the Locals, or replace the Master." That seems to suit most people fine.
For the rest... well... One time of having to reconcile, line-by-line, a config backup and whatever happened to survive in the running config after a failover event is usually enough to convince anyone too enamored with "no single points of failure" to change their tune.