Early access open now

See everything in your AD.
Change nothing.

One dashboard for your on-premises AD and cloud identity environment. Read-only by design, not by policy. Built for MSPs, IT teams, and anyone responsible for licenses they cannot see.

No credit card required. No write permissions. Ever.
Domain health
74
/ 100
Total users
1,606
Password issues
1,016
Stale computers
1,613
MFA coverage
91%
Graph API permissions
Directory.Read.All read only
User.Read.All read only
Directory.Write.* never requested
Read-only by architecture
24 report views out of the box
On-prem + M365 unified
Tested in live production
Deploy in under an hour
Built for the people who actually deal with this

If you manage users, licenses, or devices and spend too much time digging through fragmented admin portals, this is for you.

MSPs managing hybrid clients

You have 10, 20, 30 clients each running their own AD and cloud identity stack. You need visibility across all of them without logging into 30 different portals or running scripts manually every time someone asks a question.

Multi-tenant dashboard

IT teams at hybrid companies

Your company runs on-prem AD alongside a cloud identity platform and nobody has a clean picture of what is actually going on. Stale accounts, disabled users with active licenses, computers nobody has touched in two years. You know the problem.

Single-tenant dashboard

Vendor and license teams

You are responsible for cloud license spend but you have no way to see who actually uses what. You are paying for licenses assigned to people who left, to shared mailboxes that nobody opens, to accounts that have not signed in in 18 months.

License utilization reports
24 report views. One place.

Every report you actually need to understand what is happening across your on-prem AD and cloud identity environment.

01

Domain health score

Instant risk score based on password hygiene, stale accounts, MFA coverage, and privileged access. Know your posture in 10 seconds.

02

License utilization

See exactly which M365 licenses are assigned, which are active, and which are wasted on disabled or inactive accounts. Stop paying for seats nobody uses.

03

Stale account detection

Find users and computers that have not been active in 30, 90, or 180 days. Filter by OU, department, or account type.

04

Password policy audit

All password policies in one view including fine-grained policies, which users they apply to, and how many accounts have passwords set to never expire.

05

Privileged account visibility

See every admin account across on-prem AD and your cloud directory, when they last signed in, and whether they have MFA enabled.

06

PDF and CSV export

Generate a full domain health report as a PDF in one click. Export any table to CSV with your active filters applied. Send it to whoever is asking.

We never write to your environment.

Every other tool in this space requires write access. We built NexusADash so that write access is impossible, not just turned off.

Cannot modify any AD object

No user creation, no password resets, no group changes. The application has no mechanism to write to your directory.

Read-only Graph API permissions

Write scopes are not registered in the application. There is no configuration that could enable them.

Outbound-only agent

The on-prem agent connects out. Nothing connects in. No inbound firewall rules. No open ports on your network.

Self-hosted option

For regulated industries where data cannot leave the building. Full deployment on your own infrastructure.

Revoke access any time

Remove the agent or revoke the app registration and access is gone instantly. No cleanup required on our end.

Graph API permissions registered
Directory.Read.All read only
User.Read.All read only
Policy.Read.All read only
Reports.Read.All read only
AuditLog.Read.All read only
Directory.Write.* never requested
User.ReadWrite.* never requested
Write permissions are not registered and cannot be enabled through any configuration setting.
Straightforward pricing.

No per-user fees. No feature gating on reports. Pick the tier that matches your environment.

Core
$49
per month
On-premises AD only. Up to 500 users. Single tenant.
13 on-prem AD report views
Domain health score
CSV and PDF export
Single tenant
MSP
$349
per tenant / month, volume discounts below
Everything in Hybrid, built for managing multiple client environments from one place.
Multi-tenant dashboard
Per-client reporting and export
Volume pricing as you grow
Priority support

MSP volume pricing calculator

The more clients you onboard, the lower your per-tenant cost.

$349
per month / 1 tenant
1 tenant 50 tenants
1 to 5 clients
$349 / tenant
6 to 15 clients
$299 / tenant
16 to 30 clients
$249 / tenant
31 or more clients
$199 / tenant

Get early access

First 20 MSPs get 3 months free. No commitment required.

No credit card. No write access to your directory. Cancel any time.