Before you begin, make sure you have:
- A Microsoft Entra ID tenant (formerly Azure Active Directory)
- A user account with Global Administrator or Privileged Role Administrator rights in that tenant — required to grant admin consent for the Microsoft Graph permissions Nexus requests
- A Scalio Nexus account — if you don’t have one yet, contact the Scalio sales team to get access
Setup steps
1
Sign in to Scalio Nexus
Navigate to the Scalio Nexus portal and select Sign in. Use your work account — the same Microsoft identity you use for Microsoft 365 or the Azure portal. Nexus supports single sign-on via Microsoft Entra ID, so you won’t need a separate password.Once signed in, you’ll land on the Home screen with a prompt to connect your first tenant.
2
Connect your Entra ID tenant
From the Home screen, click Connect Tenant. Enter your tenant’s primary domain (for example,
contoso.onmicrosoft.com) or your Entra tenant ID (a GUID you can find in the Entra portal under Overview).Click Continue. You’ll be redirected to Microsoft’s consent page, which lists the specific Microsoft Graph permissions Nexus is requesting. Review the permissions, then click Accept to grant admin consent on behalf of your organization. Microsoft redirects you back to Nexus automatically once consent is approved.3
Wait for initial sync
After consent is granted, Nexus immediately begins an initial sync of your Entra estate — users, groups, roles, service principals, and application registrations. A progress indicator on the Tenant Setup screen shows sync status in real time.For most tenants this takes 2–5 minutes. Larger directories (50,000+ objects) may take up to 15 minutes for the first sync. Subsequent incremental syncs run continuously in the background and reflect changes within seconds.
4
Explore your dashboard
Once the initial sync completes, Nexus automatically takes you to your Identity Dashboard. You’ll see a full inventory of your Entra estate alongside your organization’s posture score, active risk flags, and a breakdown of identity health across users, groups, and applications.From here you can drill into any object, launch your first access review, or navigate to Posture Insights to explore the specific findings Nexus has identified in your tenant.
What Nexus reads from your tenant
Nexus requests the following Microsoft Graph API permission scopes during the admin consent step. All permissions are read-only — Nexus never writes to or modifies objects in your directory.
You can view and revoke Nexus’s consent grant at any time from your Entra admin center under Enterprise applications → Scalio Nexus → Permissions.
Next steps
Now that your tenant is connected, here are the best places to go next.Identity Dashboard
Learn how to navigate your identity inventory, filter by risk level, and investigate individual users, groups, and applications.
Access Reviews
Set up your first access review campaign — define scope, assign reviewers, configure recurrence, and send notifications.
Security Posture
Understand your posture score, explore individual findings, and track remediation progress over time.
Connecting Entra
Dive deeper into the tenant connection model, manage multiple tenants, and learn how to update or revoke consent grants.