Built for Microsoft Entra ID

See inside your Microsoft Entra ID, before it surprises you.

VisualizerEngine turns your Entra ID groups, nesting, and licence assignments into a live, interactive map, so you can find the circular references, inherited licences, and policy drift that the Azure portal never shows you.

Product interface preview.
Access model
Read-only Graph permissions
Performance-verified
50,000 groups · 250,000 memberships
Isolation
Row-level security, enforced in the database
Sign-in
Entra ID single sign-on, no passwords

The problem

Your directory has a shape. Microsoft never shows it to you.

Every Entra ID tenant grows the same way: groups get nested inside groups, licences get assigned to groups, people inherit access through chains nobody remembers building. The Azure portal shows you flat lists. It cannot answer the questions that actually matter.

"Why does this user have an E5 licence?"

Licence inheritance flows through nested group membership. When assignments overlap, when service plans conflict, or when a group three levels up grants a licence, the portal shows you the result but never the path.

"What happens if I move this group?"

There is no undo in a directory. Moving a group or changing a group licence cascades through every nested member, and you find out who lost access when the tickets arrive.

"Is anything circular, orphaned, or too deep?"

Circular nesting, abandoned groups, and runaway depth accumulate silently. Nothing in the native tooling flags them.

"What changed since last month?"

Directories drift. Without point-in-time snapshots, you cannot prove what changed, when, or whether you are still compliant with your own rules.

"How much licence money are we wasting?"

Duplicate assignments, disabled service plans, and unused seats hide in the same invisible structure.

The status quo

IT teams answer these questions today with PowerShell scripts, exported CSVs, and institutional memory. VisualizerEngine answers them with a picture.

The solution

Not another report. A living map of your directory.

VisualizerEngine mirrors your directory through read-only Microsoft Graph permissions, then makes its structure visible, testable, and provable.

See the structure

Explore nesting, memberships, and licence flows as an interactive hierarchy, graph, or sunburst, instead of flat lists.

Test the change

Simulate group moves and licence changes inside VisualizerEngine, and see the full blast radius before the directory is touched.

Prove the history

Capture snapshots, diff any two points in time, score policy compliance, and export reports that carry provenance metadata.

Security

What we actually enforce

Attackers already see your directory as a graph. It is time you did too. Every control listed on this site exists in the platform today, and controls we do not provide are not claimed anywhere.

Tenant isolation in the database

Every row is bound to a tenant, and Postgres row-level security is FORCE-enabled. Isolation is proven by test.

Tamper-evident audit trail

Every administrative and read action lands in an HMAC-chained, append-only audit log with chain verification.

Least privilege everywhere

Read-only Graph permissions, split database roles, and file-mounted secrets, never in code.

How it works

Live in three steps

  1. Consent

    A global admin grants read-only consent via a standard Entra admin-consent link. No agents, nothing installed.

  2. Sync

    VisualizerEngine crawls the directory once, then stays current with Microsoft Graph delta queries.

  3. See

    The full nesting map, licence flows, violations, and trends are live in your browser.

See your directory's real shape

VisualizerEngine is pre-launch. Onboarding is a read-only admin-consent link: no agents, nothing installed, nothing modified.