Early access open now

See everything in your AD.
Change nothing.

One dashboard for your on-prem AD and M365 environment. Read-only by design, not by policy. Built for MSPs, IT teams, and anyone responsible for licenses they cannot see.

No credit card required. No write permissions. Ever.
Domain health
84
/ 100
Total users
247
Password issues
18
Stale accounts
31
MFA coverage
87%
Graph API permissions
Directory.Read.All read only
User.Read.All read only
Directory.Write.* never requested
Read-only by architecture
24 report views out of the box
On-prem AD + M365 unified
Nothing installed on your DC
No inbound firewall rules
Built for the people who actually deal with this

If you manage users, licenses, or devices and spend too much time digging through fragmented admin portals, this is for you.

MSPs managing hybrid clients

You have 10, 20, 30 clients each running their own AD and M365 stack. You need visibility across all of them without logging into 30 different portals or running scripts manually every time someone asks a question.

Multi-tenant dashboard

IT teams at hybrid companies

Your company runs on-prem AD alongside M365 and nobody has a clean picture of what is actually going on. Stale accounts, disabled users with active licenses, computers nobody has touched in two years. You know the problem.

Single-tenant dashboard

Vendor and license teams

You are responsible for M365 spend but you have no way to see who actually uses what. You are paying for licenses assigned to people who left, to shared mailboxes nobody opens, to accounts that have not signed in for 18 months.

License utilization reports

Security and compliance teams

You need to know who has privileged access, which accounts have MFA disabled, and whether your password policies are actually being enforced. You need that information in seconds, not at the end of a PowerShell script.

Privileged access visibility
24 report views. One place.

Every report you actually need to understand what is happening across your on-prem AD and M365 environment.

01

Domain health score

Instant risk score based on password hygiene, stale accounts, MFA coverage, and privileged access. Know your posture in 10 seconds.

02

License utilization

See exactly which M365 licenses are assigned, which are active, and which are wasted on disabled or inactive accounts. Stop paying for seats nobody uses.

03

Stale account detection

Find users and computers that have not been active in 30, 90, or 180 days. Filter by OU, department, or account type.

04

Password policy audit

All password policies in one view including fine-grained policies, which users they apply to, and how many accounts have passwords set to never expire.

05

Privileged account visibility

See every admin account across on-prem AD and your M365 directory, when they last signed in, and whether they have MFA enabled.

06

PDF and CSV export

Generate a full domain health report as a PDF in one click. Export any table to CSV with your active filters applied. Send it to whoever is asking.

We never write to your environment.

Every other tool in this space requires write access. We built NexusADash so that write access is impossible, not just turned off.

Cannot modify any AD object

No user creation, no password resets, no group changes. The application has no mechanism to write to your directory.

NexusAD Connector, outbound only

A lightweight connector runs on any domain-joined machine at the client site. It connects outbound on port 443 only. Nothing installed on your DC. No inbound firewall rules. No open ports. Revoke access instantly by disabling the service account.

Read-only Graph API permissions

Write scopes are not registered in the application. There is no configuration that could enable them.

Your AD data stays in your account

AD data is collected by the NexusAD Connector and stored only within your isolated tenant. No other tenant can see your data. M365 data is queried live from Microsoft and never persisted on our servers.

Revoke access any time

Disable the service account or revoke the app registration and access is gone instantly. No cleanup required on our end.

Graph API permissions registered
Directory.Read.All read only
User.Read.All read only
Policy.Read.All read only
Reports.Read.All read only
AuditLog.Read.All read only
Directory.Write.* never requested
User.ReadWrite.* never requested
Write permissions are not registered and cannot be enabled through any configuration setting.

Request access

First 20 MSPs get early adopter pricing locked forever. No commitment required to get started.

No credit card. No write access to your directory. Annual plans only.