Compliance-relevant features
Nexus maps directly onto the access control and monitoring requirements found in major compliance frameworks. The table below shows which features support which compliance needs.Access Reviews
Nexus’s access review workflows generate the periodic access certifications required by frameworks such as SOC 2 CC6.3 and ISO 27001 Annex A.9.2. Every review captures reviewer decisions, justifications, and timestamps, giving auditors a complete and tamper-evident record of who certified what — and when.
Posture Insights
Continuous monitoring against zero-trust benchmarks demonstrates that your organization enforces access policies on an ongoing basis, not just at point-in-time assessments. The posture score and findings history provide auditors with evidence of active policy oversight.
Automation Rules
Automated enforcement of access policies — such as removing stale accounts or revoking excessive permissions — shows auditors that your controls operate independently of manual intervention, reducing the risk of human error and demonstrating consistent policy application.
Audit Logs
Nexus maintains a tamper-evident log of every identity change and every action taken within the platform. This log captures the who, what, when, and why of access changes across your Entra estate, supporting both internal investigations and external audit evidence requests.
Generating audit reports
Nexus lets you generate formatted audit reports on demand, covering the time range and scope that your auditor requires. You can produce a report in seconds without exporting raw data or building a spreadsheet manually.1
Go to Reports
In the Nexus left navigation, select Reports. You will see a list of any previously generated reports and a button to create a new one.
2
Select the report type
Choose the report that matches your audit evidence request:
- Access Review Summary — a complete record of all access reviews in the selected period, including completion rates, reviewer decisions, and outstanding items.
- User Access Report — a snapshot of every user’s group memberships, role assignments, and application access as of a specific date.
- Privileged Access Report — a focused view of all privileged role assignments, PIM activations, and standing admin accounts detected during the period.
- Posture History — your posture score trend, findings opened and closed, and remediation actions taken over the selected date range.
3
Set the date range and scope
Select the start and end dates for the report. Then set the scope: you can report across your entire tenant, limit the report to specific groups, or narrow it to one or more applications. Narrowing scope is useful when an auditor is reviewing a specific system or department rather than your entire environment.
4
Generate and download the report
Click Generate. Nexus processes the report and makes it available for download as a PDF or CSV within a few seconds. PDF format is suitable for sharing directly with auditors; CSV format lets you import the data into your GRC platform or compliance tracking system.
Access certification records
Every access review you complete in Nexus is permanently stored as a certification record. The record includes the full list of access items that were reviewed, each reviewer’s decision (approve, revoke, or not reviewed), any justification notes the reviewer entered, and the date and time of every decision. These records cannot be edited after the review closes, ensuring they provide a reliable audit trail. When an auditor asks for evidence that access to a sensitive application was reviewed during a specific quarter, you can produce the corresponding certification record in seconds from the Access Reviews history page. Records are retained in accordance with your organization’s data retention settings, which you can configure under Settings → Data Retention.Supported frameworks
Nexus is designed to support the access control, least-privilege, and monitoring requirements found across a range of widely adopted compliance and security frameworks. The controls Nexus provides are directly relevant to the following frameworks:SOC 2 Type II
Supports CC6.2, CC6.3, and CC7.2 controls around logical access, access reviews, and continuous monitoring.
ISO 27001
Supports Annex A.9 (Access Control) and Annex A.12.4 (Logging and Monitoring) requirements.
NIST 800-53
Maps to AC (Access Control), AU (Audit and Accountability), and IA (Identification and Authentication) control families.
CIS Controls
Supports CIS Control 5 (Account Management), Control 6 (Access Control Management), and Control 8 (Audit Log Management).
HIPAA Security Rule
Supports the Access Control standard (§164.312(a)(1)) and the Audit Controls standard (§164.312(b)) under the Technical Safeguards.
Nexus does not hold compliance certifications on your behalf. Always work with your compliance team to validate that controls meet your specific audit requirements.