Built for Microsoft Entra ID
See inside your Microsoft Entra ID, before it surprises you.
VisualizerEngine turns your Entra ID groups, nesting, and license assignments into a live, interactive map, so you can find the circular references, misplaced licenses, and policy drift that the Azure portal never shows you.

- Access model
- Read-only Graph permissions
- Performance-verified
- 50,000 groups · 250,000 memberships
- Isolation
- Row-level security, enforced in the database
- Sign-in
- Entra ID single sign-on, no passwords
01The problem
Your directory has a shape. Microsoft never shows it to you.
Every Entra ID tenant grows the same way: groups get nested inside groups, licenses get assigned to groups, people inherit access through chains nobody remembers building. The Azure portal shows you flat lists. It cannot answer the questions that actually decide your risk and your spend.

"Why does this user have an E5 license, and why doesn't that one?"
Group licensing and group access follow different rules. Access flows through nested membership, but Entra grants a group license only to that group's direct members. Nest a team under a licensed parent group and nobody in that team gets licensed. It is a documented Microsoft limitation that catches even experienced admins, and the portal never shows you which of your groups it is quietly biting.
"What happens if I move this group?"
There is no undo button in a directory. Moving a group changes access for every member nested beneath it, and you usually find out who lost access when the support tickets arrive.
"Is anything circular, orphaned, or nested too deep?"
Circular nesting, abandoned groups, and runaway depth pile up silently over the years. Nothing in the native tooling flags them for you.
"What changed since last month?"
Directories drift constantly. Without point-in-time snapshots you cannot prove what changed, when it changed, or whether you are still inside your own rules.
"How much license money are we wasting?"
Duplicate assignments, disabled service plans, and unused seats all hide inside the same invisible structure.
The status quo
Today, IT teams answer these questions with PowerShell scripts, exported spreadsheets, and the memory of whoever has been there longest. VisualizerEngine answers them with a picture, in seconds.
02The solution
Not another report. A living map of your directory.
An Entra ID visualizer built for enterprise tenants. VisualizerEngine mirrors your directory through read-only Microsoft Graph permissions, then makes its structure visible, testable, and provable, from everyday IAM questions to identity governance evidence.
See the structure
Explore nesting, memberships, and license flows as an interactive hierarchy, graph, or sunburst, instead of flat lists.
Test the change
Simulate group moves and license changes inside VisualizerEngine, and see the full blast radius before the directory is touched.
Prove the history
Capture snapshots, diff any two points in time, score policy compliance, and export reports that carry provenance metadata.
03Features
Everything the portal cannot show you
Nine capabilities, one live mirror of your directory, told in the order you will actually use them. Explore all features in depth.
See it
Three ways to see your directory
The same live directory as an interactive hierarchy tree, a force-directed graph, or a sunburst chart. Switch between them instantly and zoom from the whole tenant down to a single membership connection.

Understand it
Nesting intelligence and license truth
Circular references, depth violations, orphans, and overlapping groups are detected continuously and ranked. License analytics show every real source per user, cost by license and by group, duplicates, and the nesting license trap: every place where a license is assigned to a parent group but, per Entra's rules, never reaches the people nested below.


Change it safely
Simulate before you touch production
Model a group move or a license change first. Every simulation shows the full blast radius, who gains access, who loses it, and what happens to licensing, then generates an ordered implementation plan, all without making a single change in production.


Govern it
Policies, snapshots, and change awareness
Encode your structural rules and watch a live compliance percentage instead of dreading the audit. Point-in-time snapshots diff into exact change lists, and a notification center with a change-history view means the directory stops changing behind your back.


Work it daily
Search, reporting, and honest exports
A focused search language answers the questions you ask every week, saved for one-click reuse. Exports cover every audience: CSV and JSON, branded PDF reports, images of any view, and compliance exports with provenance. And when any part of the directory cannot be fully read, every figure is plainly marked as a lower bound.


04How it helps your company
From invisible structure to measurable outcomes

Cut wasted license spend
Duplicate assignments, unused seats, and disabled service plans are easy to miss in a spreadsheet and obvious on a map. Find the spend you can recover, and prove the savings before you change anything.
Stop access surprises before they happen
Simulate group moves and license changes and see who gains or loses access first, so a routine cleanup does not become an outage or a security gap.
Close a real security blind spot
Circular nesting, orphaned groups, and over-deep hierarchies are the quiet conditions that let access sprawl. Seeing them is the first step to fixing them.
Pass access reviews and audits faster
Point-in-time snapshots, a provable change history, and traceable compliance exports turn a stressful audit into a report you already have.
Onboard new administrators in hours, not months
A new hire understands your group structure by looking at it, instead of absorbing years of tribal knowledge.
Replace fragile scripts with a shared tool
The PowerShell that lives on one person's laptop becomes a live, shared picture the whole team can use and trust.
05Security
What we actually enforce
Attackers already see your directory as a graph. It is time you did too. Every control listed on this site exists in the platform today, and controls we do not provide are not claimed anywhere.

Tenant isolation in the database
Every record is bound to a tenant, and the database refuses cross-tenant reads at the storage layer. Proven by automated tests, not merely promised.
Tamper-evident audit trail
Every administrative and read action is written to a cryptographically chained, append-only log. If anyone alters the record, the chain check detects it.
Least privilege everywhere
Read-only access to Microsoft Graph, database roles separated so the application cannot change its own security rules, and secrets kept out of the code.
06How it works
Live in three steps
Consent
A global administrator grants read-only consent through a standard Entra consent link. Nothing is installed and no agents run in your environment.
Sync
VisualizerEngine reads your directory once to build the picture, then keeps it current with Microsoft Graph change tracking.
See
The full nesting map, license sources, violations, and trends are live in your browser, ready to explore, simulate, and export.
07FAQ
Frequently asked questions
Does it modify my directory?
No. VisualizerEngine has read-only access to groups, users, and organization information. Every simulation runs inside the product and never writes to Entra.
Do I have to install anything?
No. It is a browser-based product reached through a single administrator consent link.
Can other tenants see my data?
No. Isolation is enforced at the database record level and covered by automated tests that confirm one tenant's administrators cannot read another tenant's data.
How big a tenant can it handle?
The read path is proven at 50,000 groups and 250,000 memberships, with performance that stays fast even deep into very large directories.
See your directory's real shape
VisualizerEngine is pre-launch. Onboarding is a read-only admin-consent link: no agents, nothing installed, nothing modified.