You exaggerate, but only slightly. Whatever the theoretical properties of the windows security model, it's a failure of usability, and that means most of the time none of it gets used.
Windows is not alone in this, SELinux suffers from exactly the same problem.
Windows is not alone in this, SELinux suffers from exactly the same problem.