Your posture score
The Posture dashboard displays a single overall score between 0 and 100. A higher score means fewer open findings and a stronger alignment with zero-trust best practices. Nexus calculates this score by weighing the number and severity of open findings across four categories: Identity Hygiene, Privileged Access, MFA Coverage, and Application Security. Critical findings carry the most weight in the calculation, so closing a single critical finding can move your score significantly. Informational findings contribute less, but resolving them still reflects improvement over time. The score gives you and your leadership team a quick, at-a-glance measure of your security posture without requiring a deep dive into every individual finding.Finding categories
Nexus groups every finding into one of four categories so you can delegate remediation to the right team and understand where your exposure is concentrated.Identity Hygiene
Findings related to the cleanliness and accuracy of your user directory. Examples include stale accounts that have not signed in for 90 or more days, unmanaged guest users with no assigned owner or sponsor, and duplicate identities created when employees are provisioned more than once.
Privileged Access
Findings that expose unnecessary or uncontrolled administrative power. Examples include standing admin role assignments that should be converted to just-in-time access via PIM, roles assigned outside of Privileged Identity Management entirely, and service accounts that hold Global Administrator or equivalent rights.
MFA Coverage
Findings that identify gaps in your multi-factor authentication posture. Examples include users who have no MFA method registered, user populations excluded from conditional access policies that require MFA, and legacy authentication protocols that bypass modern authentication entirely.
Application Security
Findings related to the enterprise applications and service principals registered in your tenant. Examples include apps with delegated or application permissions that exceed what the app actually uses, apps whose client secrets or certificates have expired, and applications that have no designated owner to approve access or rotate credentials.
Remediating findings
Every finding in Nexus is designed to take you from discovery to resolution in as few steps as possible.1
Open the finding
Click any finding on the Posture dashboard or the Findings list to open its detail panel. The panel shows a plain-language description of the issue, its severity, and the date Nexus first detected it.
2
Review affected objects
The Affected Objects tab lists every user, group, role, or application that contributes to the finding. You can export this list as a CSV if you need to share it with another team or track remediation in an external ticketing system.
3
Follow the recommended action
Each finding includes a Recommended Action that tells you exactly what change needs to be made. Where Nexus can execute the remediation on your behalf — such as disabling a stale account or removing an expired application secret — a Remediate Now button appears. For changes that require human judgment or out-of-band steps, Nexus provides a numbered instruction guide you can follow directly in the Entra portal.
4
Confirm closure
After you apply the fix, Nexus re-evaluates the affected objects on the next sync cycle. If the condition is resolved, the finding closes automatically and your posture score updates to reflect the improvement.
Posture history
The Posture History chart on the dashboard plots your posture score over time, giving you a trend line that shows whether your environment is improving, stable, or regressing. You can set the time range to 7 days, 30 days, or 90 days to align with your reporting cadence. Below the chart, the Findings Changelog records every finding that was opened or closed, along with the timestamp and — for automated remediations — the Nexus action that triggered the change. This log is useful during audits to demonstrate that your team is actively monitoring and resolving identity security issues, not just tracking them.Nexus recalculates your posture score after every sync, so changes you make in Entra ID are reflected within minutes.