I'm trying to make sense of MAC, DAC, and RBAC and I'm really only confused about DAC and RBAC. I'm trying to find situations where either of these would be used in a real-world environment. Most NT environments I've worked in used something that sounds similar to the two, but can you have more than one access model in place?

For instance, DAC only assigns the least amount of power to a user. I've seen then done many times, where an administrator will assign user specific privileges applying to their work. RBAC, from what I understand, joins a user to a group that has the privileges that s/he needs.

In a network operating windows server, can these be used together? *confusion* >_o

