After you imported your existing groups and users into RSBAC UM with
rsbac_groupadd -O
rsbac_useradd -O
and set new passwords, which cannot be imported, with rsbac_passwd,
you can change the nsswitch lines

passwd:         compat
group:          compat
shadow:         compat


passwd:         rsbac
group:          rsbac
shadow:         rsbac

to let RSBAC translate between user names and uids. If you want to use
both, try

passwd:         rsbac compat
group:          rsbac compat
shadow:         rsbac compat

In /etc/pam.d/common-auth you can replace

auth    [success=1 default=ignore]      pam_unix.so nullok_secure

or similar with

auth    required        pam_rsbac.so

to use RSBAC for authentication. common-account, common-password and
common-session are similar. If you want to fallback to passwd/shadow, try

auth    sufficient      pam_rsbac.so
auth    [success=1 default=ignore]      pam_unix.so nullok_secure

