Features

Everything the portal cannot show you

One live, read-only mirror of your Entra ID directory. Nine capabilities built on top of it, from visualization to simulation to provable history.

Visualization

Three ways to see your directory

Turn 50,000 groups into one picture. Explore the same live directory as an interactive hierarchy tree, a force-directed graph, or a sunburst. Switch instantly, and zoom from the whole tenant down to a single membership edge. Built for real tenants: the engine is performance-verified at 50,000 groups and 250,000 memberships with sub-25 ms page reads.

Hierarchy tree. Product interface preview.
Force-directed graph. Product interface preview.
Sunburst, one ring per nesting level. Product interface preview.

Nesting intelligence

Find the structures that break tenants

Every circular reference, orphaned group, and depth violation, in one view.

  • Circular reference detection. Find membership loops before they break provisioning.
  • Depth analysis with your thresholds. Set the maximum nesting depth your organisation tolerates, then see every violation, ranked.
  • Orphan and overlap detection. Surface abandoned groups and groups whose memberships almost entirely overlap.
  • Members typed correctly. Users, devices, nested groups, service principals, and contacts are distinguished, so a device is never mistaken for a nested group.
Nesting analysis. Product interface preview.

License analytics

License analytics that follow the hierarchy

Trace any license to the nested group that granted it.

  • Inheritance mapping. For any user, the exact path a license travelled through nested groups to reach them.
  • Cost analysis by SKU and by group. See where the spend actually sits.
  • Conflict and duplicate detection. Overlapping assignments and disabled service plans, tracked per user.
  • Utilization alerts and recommendations. Where seats are wasted, and what to do about it.
  • Removal impact analysis. Before you unassign, know exactly who loses what.
License analytics. Product interface preview.

What-if simulation

Simulate the change. See who loses access. Then decide.

Model a group move or a license change before touching the directory. Build multi-step scenarios, compare them side by side, and generate an ordered implementation plan.

Every simulation shows the full blast radius: who gains access, who loses it, which licenses cascade.

What-if simulation. Product interface preview.

Policy engine

Governance as a trend you watch, not an audit you dread

Encode your governance rules, from nesting depth to structural constraints, using templates or building from scratch. VisualizerEngine scores every violation, computes a live compliance percentage, and plots drift over time.

Compliance dashboard. Product interface preview.

Snapshots and trends

Prove exactly what changed

Capture point-in-time snapshots of the directory. Diff any two to see exactly what changed. Watch structural and license trends on a dashboard instead of reconstructing history from memory.

Snapshot comparison. Product interface preview.

Reporting and exports

Evidence you can hand to anyone

  • CSV and JSON exports of the full hierarchy and analytics.
  • PDF reports with your own branding.
  • PNG and SVG image export of any visualization.
  • Compliance exports carrying provenance metadata and an integrity trailer, so a report can be traced back to the data that produced it.
Export dialog. Product interface preview.

Change awareness

The directory stops changing behind your back

A notification centre with configurable alerts and a change-history panel keeps every structural and license change visible.

Notification centre. Product interface preview.

See your directory's real shape

VisualizerEngine is pre-launch. Onboarding is a read-only admin-consent link: no agents, nothing installed, nothing modified.