Skip to main content
The Identity Dashboard is your command center for the entire Microsoft Entra estate. It consolidates users, groups, applications, and service principals into one searchable, filterable view with health and risk indicators. Whether you’re preparing for an audit, investigating a risk flag, or simply getting a handle on who has access to what, the dashboard surfaces the information you need without requiring you to jump between the Entra portal, Azure, and Microsoft 365 admin center.

What you’ll see

The dashboard is organized into panels that each reflect a key area of your identity estate. All counts and indicators update on every sync cycle so you’re always looking at current data.

User Inventory

Displays the total number of users in your tenant, broken down by member users, guest users, and inactive users — defined as accounts with no recorded sign-in activity in the last 90 or more days. Use this panel as your first stop when assessing account hygiene.

Group Inventory

Shows all groups in your tenant categorized as security groups, Microsoft 365 groups, and dynamic groups. Dynamic groups are flagged separately so you can quickly identify memberships that change based on attribute rules.

Applications

Lists all application registrations and enterprise applications in your tenant. Each entry shows its publisher, consent status, and the number of users or groups assigned to it.

Service Principals & Managed Identities

Enumerates every service principal and managed identity, including workload identities created by Azure resource deployments. This panel is especially valuable for teams practicing zero-trust by ensuring non-human identities are tracked and reviewed.

Risk flags

At the top of the dashboard, Nexus surfaces a set of tenant-wide risk indicators that demand immediate attention:
  • Accounts with no MFA registered — users who have not set up any multi-factor authentication method.
  • Privileged accounts without PIM — directory role members whose assignments are permanent rather than time-bound through Privileged Identity Management.
  • Stale guest accounts — guest users who have not signed in within the last 30 days and have not been reviewed.
Privileged accounts without PIM represent a significant standing-access risk. Nexus flags these prominently because permanent role assignments are one of the most common findings in security reviews.

Filtering and searching

Every panel in the dashboard supports inline filtering so you can narrow the data to exactly what you need. Use the Filter bar above any panel to refine results by:
  • User type — member, guest, or service account
  • Risk level — high, medium, low, or none (based on Nexus risk scoring)
  • Group membership — show only users who belong to a specific group
  • Last sign-in date — filter to users who have or have not signed in within a custom date range
For targeted lookups, use the Search bar at the top of the dashboard. You can search by display name, UPN, application name, object ID, or group name. Results appear across all object types simultaneously, so a single query surfaces matching users, groups, and apps in one place.
Search is backed by your tenant’s synced data, not a live Entra query. If you’ve just made a change in the Entra portal, wait for the next sync cycle — typically every 15 minutes — before it appears in Nexus search results.

Drilling into a user or object

Clicking any user, group, application, or service principal in the dashboard opens a detail panel on the right side of the screen. The detail panel consolidates everything Nexus knows about that object in one place:
  • Assignments — every group the user belongs to, every app they can access, and any directory roles assigned to them
  • Roles — both direct role assignments and group-inherited roles, with PIM eligibility status
  • Last activity — last sign-in timestamp, last password change, and last MFA registration update
  • Active risk flags — a list of any risk conditions currently associated with the object, with links to the relevant remediation action
From the detail panel you can take immediate action: initiate an on-demand access review, disable the account, or add the object to a remediation queue — all without leaving the dashboard.

Exporting data

When you need to share findings with stakeholders or attach evidence to an audit, click the Export button in the top-right corner of any panel. Nexus generates a CSV file reflecting the current filtered view — including all visible columns and applied filters. Exports are timestamped and include your tenant ID, making them suitable for compliance records. You can export any of the following views:
Use the Inactive Users filter to quickly identify accounts that may need to be reviewed or disabled. Exporting this filtered view gives you a ready-made remediation list you can hand off to your IT team.