Limit Global Administrators — the 2–4 band, what PIM does to the count, and the export reviewers accept
"How many Global Administrators do you have?" looks like the easiest question on the renewal form, and it's the one where the confident answer is most often wrong. The number in your head is usually the direct assignments you remember making. The number that matters includes group members, eligible assignments, and whoever can edit either.
The part checklists get wrong
The threshold is a band, not a minimum. CIS M365 v6 (1.1.3) puts it at 2–4 Global Administrators; CISA SCuBA (MS.AAD.7.1) allows 2–8. The upper bound is the familiar blast-radius argument. The lower bound is the one checklists skip: a single GA is a single point of failure, and a tenant locked out of its only admin account is a support case measured in days. One is a finding in both frameworks, same as nine.
The two frameworks disagree, so a tenant with six GAs passes SCuBA and fails the stricter band. Know which bar your questionnaire is quoting before you answer.
PIM changes what "count" means
Without PIM, the count is one number: standing assignments. With PIM (Entra ID P2 or Microsoft Entra ID Governance), it splits into three — permanently active, currently activated, and eligible — and the honest answer names all three. The zero-standing-access end state most tenants should aim for: two break-glass accounts permanently active, every working admin holding an eligible assignment activated just-in-time. That tenant reports "2 standing, N eligible" and sits comfortably inside both bands on the number that measures live exposure.
What PIM does not do is make eligible admins disappear. An eligible assignment is still a credential path to Global Administrator, and a reviewer who knows to ask will want the eligible list too — with activation requirements (MFA, approval, time-bound) attached as the reason the number is acceptable.
The role-assignable groups trap
Assign GA to a role-assignable group and the role page shows one row while granting the role to every member. Two counting errors follow. The obvious one: eyeballing the role page and reporting the row count. The subtle one: the group's owners can add members at will, which makes every owner a Global Administrator in effect while appearing on no role list anywhere. Any count that doesn't expand groups and enumerate their owners is undercounting.
Proving it with a dated export
Screenshots of the role page don't survive the questions above. Export the assignments with Graph PowerShell:
Connect-MgGraph -Scopes "RoleManagement.Read.Directory"
$ga = "62e90394-69f5-4237-9190-012177145e10" # Global Administrator role
Get-MgRoleManagementDirectoryRoleAssignment -Filter "roleDefinitionId eq '$ga'" -ExpandProperty Principal
Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -Filter "roleDefinitionId eq '$ga'"
Where a principal is a group, list its members and its owners and include both. Date the export, state the three counts (standing, activated, eligible), and attach one line per standing assignment saying why it can't be eligible instead. That last column is the difference between an export and evidence.
How Calibrant checks this
Calibrant carries the two thresholds as two separate checks — the stricter 2–4 band from its own baseline, and SCuBA's 2–8 range — so a tenant sees exactly which bar it clears rather than one blended verdict. PIM usage is a further check of its own, and it's capability-gated: it requires the PIM service plan (Entra ID P2 or Microsoft Entra ID Governance), and a tenant whose licensing lacks it is not scored as failing a control it can't configure. Each scan produces a dated assessment report, which is the same artifact the renewal exchange above keeps asking for.
Early access is by invite — code SEO-GLOBAL-ADMINS at calibrant.ai.