What you’ll see
The dashboard is organized into panels that each reflect a key area of your identity estate. All counts and indicators update on every sync cycle so you’re always looking at current data.User Inventory
Displays the total number of users in your tenant, broken down by member users, guest users, and inactive users — defined as accounts with no recorded sign-in activity in the last 90 or more days. Use this panel as your first stop when assessing account hygiene.
Group Inventory
Shows all groups in your tenant categorized as security groups, Microsoft 365 groups, and dynamic groups. Dynamic groups are flagged separately so you can quickly identify memberships that change based on attribute rules.
Applications
Lists all application registrations and enterprise applications in your tenant. Each entry shows its publisher, consent status, and the number of users or groups assigned to it.
Service Principals & Managed Identities
Enumerates every service principal and managed identity, including workload identities created by Azure resource deployments. This panel is especially valuable for teams practicing zero-trust by ensuring non-human identities are tracked and reviewed.
Risk flags
At the top of the dashboard, Nexus surfaces a set of tenant-wide risk indicators that demand immediate attention:- Accounts with no MFA registered — users who have not set up any multi-factor authentication method.
- Privileged accounts without PIM — directory role members whose assignments are permanent rather than time-bound through Privileged Identity Management.
- Stale guest accounts — guest users who have not signed in within the last 30 days and have not been reviewed.
Filtering and searching
Every panel in the dashboard supports inline filtering so you can narrow the data to exactly what you need. Use the Filter bar above any panel to refine results by:- User type — member, guest, or service account
- Risk level — high, medium, low, or none (based on Nexus risk scoring)
- Group membership — show only users who belong to a specific group
- Last sign-in date — filter to users who have or have not signed in within a custom date range
Search is backed by your tenant’s synced data, not a live Entra query. If you’ve just made a change in the Entra portal, wait for the next sync cycle — typically every 15 minutes — before it appears in Nexus search results.
Drilling into a user or object
Clicking any user, group, application, or service principal in the dashboard opens a detail panel on the right side of the screen. The detail panel consolidates everything Nexus knows about that object in one place:- Assignments — every group the user belongs to, every app they can access, and any directory roles assigned to them
- Roles — both direct role assignments and group-inherited roles, with PIM eligibility status
- Last activity — last sign-in timestamp, last password change, and last MFA registration update
- Active risk flags — a list of any risk conditions currently associated with the object, with links to the relevant remediation action