Hype Cycle for Digital Identity, 2025

ARCHIVED
14 July 2025 - ID G00830736 - 127 min read
By Nayara Sangiorgio, Nathan Harris
Digital identities are the cornerstone of cybersecurity, empowering secure access, threat detection, compliance and digital transformation. Cybersecurity leaders should leverage this research to drive innovation and enable secure, agile digital business.

Analysis


What You Need to Know

The current landscape of digital identity is characterized by rapid advancements, promising innovations and increasing complexity.
The importance of machine identity and access management (IAM) is shaping the digital identity landscape, as organizations are starting to actively manage the large number of workload and device identities in their environment to reduce risk and increase efficiency.
AI technologies are being employed to detect anomalies indicative of fraudulent activities and unusual behavior patterns. While security-efficient AI-driven automation of routine IAM tasks and AI-optimized threat intelligence initiatives are promised, the efficacy of such approaches has yet to be quantified at scale.
Standards supporting digital identity are evolving and gaining traction, with new standards such as OpenID for verifiable credentials (OID4VC), OpenID Connect, Risk Incident Sharing and Coordination (RISC) and AuthZEN becoming more popular.
Decentralized identity models are seeing growing adoption across government-citizen and organization-workforce use cases. New standards for verifiable credentials promise interoperability across such platforms.

The Hype Cycle

Authentication methods continue to mature. Adoption of device-bound passkeys has seen a significant increase; however, adoption of multidevice passkeys remains further behind in comparison. Authentication gained a new innovation on this year’s Hype Cycle with postquantum authentication (PQA), and Gartner anticipates this being a critical component of future-proofing organizations with support for algorithms that withstand quantum attacks.
Innovations that enhance confidence in real-world identity claims are increasingly being adopted across various use cases and industries. This year, two notable advancements in identity verification have emerged. First, identity verification (IDV) for the workforce has gained traction due to the significant rise in attacks on help desks and on the hiring process. Second, deepfake detection in enterprise meeting solutions is developing as a response to deepfake-enhanced social engineering attacks directly on employees.
OID4VC enters this year’s Hype Cycle. This is a set of standards that enables secure, privacy-preserving and interoperable issuance of verification of digital credentials.
There is increasing interest in the adoption of strong machine identity management controls. Machine IAM is a practice supported by multiple technologies, some of which are covered as individual innovations in this Hype Cycle. Secret management tools have been developed to securely control access to workloads by centralizing control over secrets. This Hype Cycle adds Secure Production Identity Framework for Everyone (SPIFFE) as a modern protocol that provides robust mechanisms for managing ephemeral workload identities.
AI’s impact on digital identity is increasing and expanding this year. This is reflected by the addition of cybersecurity AI assistants and AI-native software engineering, both of which bring value to digital identity by accelerating IAM technology development and application integration into IAM systems.
Additionally, the drive for AI adoption has highlighted the heavy data dependency of digital identity capabilities and the gap in the industry of effective data management capabilities. Identity visibility and intelligence platforms provide a more robust, comprehensive visibility layer for IAM programs.
Figure 1: Hype Cycle for Digital Identity, 2025
Hype Cycle for Digital Identity, 2025 plots 30 innovations from the Innovation Trigger through the Plateau of Productivity. Innovations range from postquantum authentication to cybersecurity AI assistants to passive behavioral biometrics.

The Priority Matrix

High-value innovations nearing maturity in this Hype Cycle and represented in the Priority Matrix revolve around verifiable credentials (VCs), identity wallets and decentralized identity. These technologies establish, broker and manage trust in digital identities, while allowing users to own their digital identities.
AI-augmented and AI-native software engineering are increasingly used in the digital identity space. Organizations should seek tools that leverage these advancements to speed up integration to digital identity services.
Passkeys are seeing increased adoption, with device-bound passkeys being adopted more widely than multidevice passkeys, enhancing security and UX. Age assurance and parental consent tracking technology has also grown rapidly, driven by global regulatory demands and large technology platforms preemptively adopting child restrictions in response.
OpenID Connect, a widely supported digital identity standard, enables easy integration between applications and identity services. Organizations are encouraged to adopt such standards as they reach maturity over the next two years.
Identity threat detection and response (ITDR) practices and tools are now essential for detecting and responding to threats targeting identities. Additionally, improved machine IAM features are making it easier for organizations to manage risks and streamline development.
Identity visibility and intelligence platforms are new to the Hype Cycle this year and can potentially enable rapid improvements in digital identity programs by providing a single pane of glass view of identities and access with actionable insights and recommendations.

Priority Matrix for Digital Identity, 2025

BenefitYears to Mainstream Adoption
Less Than 2 Years2 to 5 Years5 to 10 YearsMore Than 10 Years
Transformational
High
Moderate
Low
Source: Gartner (July 2025)

Off the Hype Cycle

  • The OAuth 2.0 standard is now the de facto standard for access control for API usage and has the advantage of no viable competing standards. It has reached mainstream adoption levels across industries and regions, though some process challenges remain in API access control more broadly.
  • Identity verification (IDV) has reached mainstream in customer-facing applications, with over 50% of adoption in customer use cases. Historically, IDV was used in customer-facing use cases such as regulated know-your-customer (KYC) onboarding. It then expanded into other customer-facing use cases such as those related to reducing fraud in high-risk transactions, travel and healthcare, and promoting trust and safety on marketplace platforms.
  • Zero-knowledge proofs was removed. Zero-knowledge proofs (ZKP) and zero-knowledge claims (ZKC) are a useful cryptographic protocol for selective disclosure of data; their use case is in proving a claim without revealing any additional information about that claim. Last year, Gartner flagged this technology as obsolete prior to reaching the Plateau of Productivity, meaning that we do not believe it will ever progress all the way through the Hype Cycle. Adoption has mostly stalled outside of the decentralized identity space, and we are seeing more modern approaches being favored. Gartner will continue to cover ZKC/ZKP but feels it is no longer appropriate to include this on the Hype Cycle.

On the Rise

AI-Native Software Engineering

Analysis By: Manjunath Bhat, Mark Driver
Benefit Rating: Transformational
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
AI-native software engineering is an emerging set of practices and principles that are optimized for using AI-based tools to develop and deliver software applications. This entails AI autonomously or semiautonomously performing a significant percentage of the tasks across the software development life cycle (SDLC). For example, developers use AI agents that proactively recommend and execute actions by sensing inputs from development environments with the goal of automating end-to-end workflows.
Why This Is Important
Today, developers use AI-based tools such as AI code assistants and AI testing tools that are limited to coding and testing activities. However, Gartner predicts a future where AI will be integral and native to most software engineering tasks, changing both the nature of developers’ work and their way of working. AI-native software engineering practices are important because they enable developers to focus on meaningful tasks that require critical thinking, human ingenuity and empathy.
Business Impact
AI-native software engineering has the potential to deliver numerous benefits for developers, product teams and business stakeholders alike. AI-based tools will help developers go beyond handling drudgery. These tools will serve as ideation partners that boost human creativity and support product teams in generating new ideas. Product teams can use AI-enabled analysis to make data-driven product roadmap decisions that either validate or refute subjective human decisions. Then, teams can expedite creating prototypes to speed up feasibility studies and chart an informed path forward.
Drivers
  • Achieving step change in productivity and performance: Software engineering has become AI-augmented with the emergence of AI-based developer tools, but the overall method and SDLC haven’t yet transformed. AI augmentation has been applied to many tasks within the traditional SDLC to provide incremental improvements in lead time, cycle time and quality. This is driving software engineering leaders to explore ways to achieve a step change in productivity and performance.
  • Boosting human creativity: Teams can leverage multimodal capabilities in AI-based development tools to boost human creativity. Instead of staring at a blank canvas, a product manager or UX designer can use AI design tools to convert text prompts, screenshots or paper sketches to images and visual prototypes. They can then iterate on the design and, once the design is finalized, UX designers can convert those designs to HTML and cascading style sheets (CSS).
  • Translating intent into action: Early previews of AI-native application builders, such as Bolt from StackBlitz, Firebase Studio from Google, v0 from Vercel, and Lovable, demonstrate the ability to translate user intent into actions. Users can describe requirements from an end-user perspective rather than technical specifications. This signals a fundamental shift in how we express intent to computers — going from precise instructions to describing the desired state in natural language. Andrej Karpathy, the cofounder of OpenAI and founder of Eureka Labs, coined the term vibe coding to describe this new programming paradigm where you “forget the code even exists.” Note that vibe coding as defined is currently limited to experimental prototypes and not suited to take applications to production.
  • Generating positive developer sentiment: Developers, in general, are keen on experimenting with new tools. A recent Gartner survey of 5,112 software development team members from 51 organizations shows that 54% of software development team members consider having freedom to experiment and innovate as one of the most important aspects of the developer experience. Positive developer attitudes toward AI is driving the adoption of AI-native engineering practices within organizations.
Obstacles
  • Overly trusting AI outputs: AI-native approaches create a new burden on developers and knowledge workers in general. Developers increasingly offload tasks to AI-based tools, which carry inherent risks of nondeterminism and hallucinations. Therefore, blindly trusting AI outputs without verification and explainability can potentially pose serious business risks, including reputational damage. GitClear’s 2025 AI Copilot Code Quality Report shows four times more code cloning and a spike in the prevalence of duplicate code blocks between 2023 and 2024 compared to previous years.
  • Increased security risk: AI tools expand the threat surface to include the chain of all events and interactions they initiate and participate in — including those that are invisible to human or system operators. This expanded threat surface increases the potential for unforeseen vulnerabilities and security breaches. Developers must account for agentic workflows as part of assessing and mitigating software supply chain risks.
  • Compounded risk of hallucinations in multiagentic workflows: The risk of hallucinations compounds in multiagentic workflows, where AI-generated context is passed from one AI agent to another. Model overreach is also an issue with agentic systems — where the model does more than asked because in the training data it often goes further than just the bit you need. For example, you may ask for it to write a script for “search” and it creates one that does “search and replace.”
User Recommendations
  • Rethink developer workflows by taking advantage of emerging AI-based tools and technologies to improve productivity and enhance creative upstream work. Examples of upstream use cases include product discovery, product design, user sentiment analysis and feature prioritization.
  • Unlock greater gains in productivity and minimize hallucinations by sharing context between AI-enabled developer tools (potentially AI agents) as they transition work from one tool to another.
  • Prioritize low-risk and high-value use cases for agent-based tools by assessing their ability to automate repetitive work and keep humans in the loop for oversight, verification and explainability. To sustain high quality, human developers must review code, use test harnesses and establish security and compliance guardrails throughout the software development life cycle.
  • Explore ways to benefit from autonomous improvement loops by segmenting tasks based on business criticality, risk threshold and task complexity. Software engineering leaders will need to look for opportunities where these autonomous loops deliver business value without increasing risks.
Sample Vendors
Anysphere; CodeStory; GitHub; Google; Lovable; Replit; StackBlitz; Vercel; Windsurf; Zed Industries
Gartner Recommended Reading
Innovation Insight for AI-Native Software Engineering

OID4VC

Analysis By: Michael Kelley, Akif Khan
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
OpenID Connect (OIDC) is a well known open standard for SSO in AM platforms and has served to make SSO more available across many disparate systems. OpenID for Verifiable Credentials (OID4VC) is a collection of open standards and protocols that makes creation, exchanges and validation of identity data held within verifiable credentials possible among disparate decentralized identity (DCI) systems.
Why This Is Important
As more decentralized identity (DCI) vendors and use cases surface, one of the most significant challenges for DCI will be interoperability for verifiable credentials enabling the ability to use digital wallets to prove identity claims while on disparate trust networks. OID4VC can enable open standards for the interaction of verifiable credentials created on disparate DCI products or networks. This step will be foundational for the adoption of more universal DCI use cases in the market, as well as the growth of DCI in general.
Business Impact
One of the primary challenges for the application of verifiable credentials is identifying use cases that will make sense and are achievable today. But unless the interoperability challenge is solved, the value created by these use cases will remain siloed and regional. The adoption of open standards for the exchange of verifiable credentials will allow the DCI market to grow and allow more DCI business use cases to be explored. Two primary business benefits of those use cases are optimization and cost reduction.
Drivers
  • The need for open standards developed to exchange identity data and attributes contained in verifiable credentials, including;
    • OpenID for Verifiable Credential Issuance — Defines an API and corresponding OAuth-based authorization mechanisms for issuance of Verifiable Credentials (Editors’ Draft) (Working Group Draft)
    • OpenID for verifiable presentations — Defines a mechanism on top of OAuth 2.0 to allow presentation of claims in the form of verifiable credentials as part of the protocol flow (Editors’ Draft) (Working Group Draft) (Implementer’s Draft)
    • Self-Issued OpenID Provider v2 — Enables End-Users to use OpenID Providers (OPs) that they control (Editors’ Draft) (Working Group Draft) (Implementer’s Draft)
  • OID4VC is supported by many major vendors, but requires more standardization guidance in terms of how vendors build their DCI products and for enablement for interoperability among discrete networks.
  • OID4VC is credential format agnostic, making it useful in a variety of contexts.
  • Cybersecurity — OID4VC is a foundational component in the developing market of DCI. DCI is a disruptive IAM technology, taking a different approach to the use and storage of identity data.
  • Privacy — OID4VC enables DCI features, including providing privacy for participants, primarily through consent management and through the use of privacy preserving protocols such as zero-knowledge proofs (ZKPs), which provide pseudonymity.
  • Cost optimization Verifiable credentials contain proofs for claims about identity attributes, like employment status, citizenship or authorizations to access applications and data. OID4VC promises interoperability among any DCI system, representing magnitudes of improvement in terms of efficiency, cost and assurance over current approaches.
Obstacles
  • The DCI market, while established, is nascent and struggling to attract the attention and focus compared to other, more established markets like access management and authentication. This will delay efforts to adopt open standards like OID4VC.
  • Other protocols and standards related to verifiable credentials are highly in flux. The dynamic nature of standards development will delay widespread adoption as anyone other than early adopters will wait to see how the market progresses.
  • OID4VC is highly dependent on the success of large, complex DCI initiatives, requiring the portability of verifiable credentials across multiple trust fabrics that OID4VC enables. If the DCI market fails to prove valuable for solving global challenges, OID4VC adoption will be impacted.
User Recommendations
  • For existing verifiable claims use cases, explore using OID4VC for interaction with other identity trust fabrics for issuing, exchanging or validating verifiable credentials.
  • Track maturity of the OID4VC standards and leverage the standards for use cases that would provide value outside of a confined DCI ecosystem.
  • When possible, participate in standardization bodies like OpenID Foundation, Decentralized Identity Foundation and Trust OverIP to help further define developing open standards like OID4VC.
Sample Vendors
Authlete; Curity; IBM; Microsoft; Okta; Ping Identity; SpruceID
Gartner Recommended Reading

Postquantum Authentication

Analysis By: Ant Allan, Sarah Almond, James Hoover, Paul Rabinovich
Benefit Rating: High
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Postquantum authentication (PQA), also known as quantum-safe authentication (QSA), is a horizontal category that encompasses any authentication method that incorporates postquantum cryptography (PQC) to mitigate attacks using quantum computing. This innovation cuts across different flavors of authentication, especially phishing-resistant MFA based on public-key cryptography (X.509, FIDO2), but also includes mobile push methods.
Why This Is Important
Authentication should provide credence in an identity claim, sufficient to bring account takeover (ATO) risks within an organization’s risk tolerance. By 2029, advances in quantum computing will weaken and break the conventional asymmetric cryptography that underpins many authentication methods. This will significantly reduce the credence that these methods can provide, increasing enterprises’ exposure to ATO risks. Thus, migration to postquantum authentication is a critical task.
Business Impact
PQA is crucially important to identity and access management (IAM) and other cybersecurity leaders:
  • In all industry verticals and geographies
  • Across multiple use cases incorporating authentication methods based on asymmetric cryptography
  • To protect these methods from attacks based on advances in quantum computing
  • To avoid increasing the organizations’ exposure to ATO risks and consequent data breaches, financial loss and so on.
Drivers
  • Public-key cryptography underpins three important flavors of authentication tokens: mobile push, X.509 and FIDO2; the latter two provide phishing-resistant MFA.
  • Mobile push is one of the most popular authentication methods. Mobile push apps typically embed public-key credentials, used to sign the user’s response and provide data integrity and data origin authentication, confirming possession of the token (smartphone).
  • Phishing-resistant MFA is of increasing client interest as a way of avoiding the vulnerabilities of other token-based MFA (including mobile push). Both X.509 and FIDO2 flavors incorporate public-key credentials in the sole possession of the user, activated​ by a local PIN or biometrics​.
  • Key cracking is one of the mathematically approachable problems the new generation of commercial quantum computers are positioned to solve. Gartner predicts that by 2029, quantum computing will make conventional asymmetric cryptographic systems unsafe to use.
  • In many classes of systems, replacing existing algorithms has begun and is expected to accelerate now that NIST has identified new quantum-safe algorithms and drafted deprecation dates for classical asymmetric algorithms.
  • Commercial PQA (i.e., authentication that incorporates quantum-safe algorithms) is currently (July 2025) generally available from only one specialist vendor. Thus, it is still at a far left position on the Hype Cycle.
  • Adoption is likely to be slow for the next 2 years. However, Gartner projects that adoption will increase rapidly as mainstream authentication vendors bring their PQA tools to market, enabling organizations to implement and roll out PQA comfortably ahead of the 2029 deadline. Thus, we project that PQA will reach the Plateau of Productivity quite rapidly.
  • Vendors that lag in making PQA generally available are likely to lose customers, who will seek new partners that can enable a timely implementation and roll out.
Obstacles
  • Organizations may lack a full inventory of where vulnerable authentication methods are used and who the stakeholders are. It may be difficult to orchestrate change across all dependent parties.
  • There is a key dependency on the FIDO Alliance and individual authentication vendors for PQA, but most plans are at early stages.
  • FIDO2 and X.509 methods depend on algorithm standardization and incorporation into various protocols, as well as updates to OSs, browsers, devices (especially Trusted Platform Modules [TPMs]) and other infrastructure. Some proprietary offerings may be free of such prerequisites.
  • Authentication vendors may be late incorporating PQC within their tools. PQA must be generally available sufficiently early, ideally by 2027, to enable organizations’ timely migration to PQA. If vendors are late, customers should seek alternative providers.
  • Implementing and rolling out PQA will mean updating authenticators and reprovisioning these to every user, a significant logistical effort that may present opportunities for ATO attacks.
  • Supply chain constraints may impact sourcing new PQA compliant hardware tokens, impacting timelines and budgets.
User Recommendations
  • Include PQA within a comprehensive postquantum program. While PQA might not be a high priority in terms of data value and “harvest now, decrypt later” exposure, it may still need significant effort and early discovery/inventory is a priority.
  • Work with incumbent vendors to understand their timeline for PQA. Seek support for hybrid methods to enable a robust transition to pure PQA.
  • If selecting new tools, prefer vendors in this order: those that offer PQA. Otherwise, prefer vendors that have a clear timeline for PQA over any that don’t.
  • Establish a clear setback schedule that will give you sufficient time to select, implement and roll out a new PQA tool. Use this to set a watershed. If an incumbent vendor cannot offer PQA at that time, be prepared to switch.
  • In any case, ensure timely PQA rollout. Be wary of attacks against credential management processes. Reprovision authenticators ahead of time so the process can be bootstrapped using existing methods. Later (re)provisioning will require more onerous identity verification steps.
Sample Vendors
Wultra
Gartner Recommended Reading

IDV for Workforce

Analysis By: James Hoover, Akif Khan
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Workforce identity verification (IDV) seeks to apply IDV tools and techniques to high-risk portions of the employee identity life cycle — from precredentialed events such as recruitment, to credential issuance at onboarding, to unauthenticated interactions such as credential recovery.
Why This Is Important
Credential management processes are increasingly targeted by attackers for initial access to an organization’s resources. Established accounts can be attacked through reset processes for authentication, where an attacker seeks to have their authentication token associated with the target’s account. Attackers too increasingly target the employee recruitment pipeline to gain access, whether to perform subsequent malicious action or to bypass sanctions and funnel money to restricted regimes.
Business Impact
Cybersecurity leaders across all industry verticals and geographies can benefit from incorporating IDV tools into workforce scenarios, which can:
  • Provide credence in an identity claim made by an individual that is not yet known to the organization or is unable to authenticate due to a loss of access to configured credentials.
  • Provide insulation against deepfakes that may be used to subvert processes that rely on an individual’s judgment.
Drivers
  • Increasing adoption of phishing-resistant multifactor authentication (MFA) is pushing attackers to seek methods of gaining access that do not require technically sophisticated attacks, such as social engineering.
  • Rising candidate fraud, coupled with the prospect of legal consequences when unknowingly hiring citizens of a sanctioned regime.
  • Conventional service desk verification processes are based on familiarity and gaining the confidence of the agent, and are vulnerable to both social engineering and deepfakes.
  • Typical processes around remote onboarding involve checks for the existence of an identity and/or work eligibility, but do not provide assurance that the individual presenting an identifier is its owner (i.e., a background check does not confirm a person’s identity, merely that an identity exists).
Obstacles
  • Novelty/lack of familiarity with IDV within a workforce context.
  • Privacy concerns from the workforce, notably around the topic of biometric data.
  • Inconsistent support for workforce use cases among IDV vendors.
  • Entrenched administrative processes designed to build confidence in a person’s identity.
  • Lighter-weight alternatives, such as the use of decentralized identity (e.g., Entra Verified ID) that may not require the use of a full IDV beyond one-time enrollment.
  • As they have classically been used as antifraud and compliance measures, IDV tools tend to be opaque in their decision making. This lack of transparency makes it difficult for their conclusions about an identity to be acted on in a meaningful way by end-user organizations with specific goals around risk and response.
User Recommendations
  • Explore IDV capabilities provided by already deployed access management or authentication tools.
  • Deploy compensating controls for the highest-risk unauthenticated scenarios.
  • Gauge the appetite of your organization for full IDV deployment, and explore alternatives that can provide confidence in an identity claim without a full doc + selfie process, if needed.
  • Deploy IDV tools where feasible, especially as part of onboarding and during unauthenticated contacts with the service desk.
Sample Vendors
1Kosmos; HYPR; Incode; iProov; Nametag; Persona; Ping Identity; Trusona
Gartner Recommended Reading

AuthZEN

Analysis By: Mehmet Yaliman, Paul Mezzera
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
AuthZEN is an authorization standard developed within the OpenID Foundation that focuses on defining protocols for evaluating user permissions and access rights across systems and applications. It aims to simplify the authorization process by providing a standardized interface that enhances security and ensures consistency in how access decisions are made.
Why This Is Important
Applications often build their own authorization systems or integrate with externalized authorization management (EAM) tools through proprietary means, causing low to nonexistent interoperability and an increase in vendor lock-in. AuthZEN brings much-needed, standardized interoperability to authorization to simplify implementation, reduce costs, enable more sophisticated access control, and accelerate the widespread adoption of externalized authorization management systems.
Business Impact
Adopting AuthZEN:
  • Reduces effort and complexity by simplifying fine-grained authorization with a standard interface, eliminating custom-made integrations.
  • Accelerates adoption by promoting externalized authorization in applications.
  • Centralizes authorization policy management for improved auditability and compliance.
  • Ensures consistent access control and dynamic authorization decisions.
  • Decreases reliance on proprietary systems, thereby reducing the risk of vendor lock-in.
Drivers
  • Integrating with shared authentication services is considered a “solved problem” due to standards like OAuth 2.0 and OpenID Connect (OIDC), particularly for single sign-on. This allows the industry to focus on the less mature, but crucial, area of authorization.
  • Authorization lacks universal standards for integration and interoperability, resulting in a fragmented landscape. Many applications develop proprietary access control systems or rely on constrained authorization patterns, so that managing authorization across diverse applications becomes complex, costly and hard to secure.
  • Modern security strategies, such as Zero Trust, demand dynamic, fine-grained authorization decisions based on identity, resources, actions and context. This requires continuous evaluation beyond simple checks. Decoupling authorization logic from applications and managing it centrally through policy-based systems enhances security, auditability, and flexibility, and simplifies development. AuthZEN supports this by offering a standardized method for applications to delegate authorization decisions to external platforms, independently of the authorization framework(s) in use.
  • AuthZEN aims to become the “OIDC of authorization,” drawing industry interest by promising to standardize authorization like OIDC did for authentication. Standardization is vital for increasing interoperability and accelerating the adoption of EAM tools.
  • The AuthZEN working group has achieved Implementer’s Draft status for the Authorization API version 1.0, focusing on standardizing communication between Policy Enforcement Points (PEPs) and Policy Decision Points (PDPs) using a JSON-based model. Demonstrating interoperability among vendors using the AuthZEN protocol is a significant milestone, with successful interop events at conferences like the Gartner IAM Summit London 2025. Leading authorization vendors are participating in the working group, committing to adopt and integrate AuthZEN into their products.
Obstacles
  • Authorization today is implemented in a multitude of locations, through diverse tooling, and is based on varying paradigms. This inherent complexity makes standardization more difficult compared to authentication.
  • There is currently very little adoption of AuthZEN as implementers wait to see if it is viable in the long term. The Authorization API 1.0 is at the “Implementer’s Draft” stage, indicating that while vendors are starting to integrate it, it has not yet achieved the status of a final, universally adopted standard. The working group remains actively engaged in defining the necessary patterns, mechanisms, protocols and formats.
  • Many applications lack inherent support for modern identity protocols, with authorization trailing behind authentication and provisioning. Integrating externalized authorization necessitates that applications are designed or modified to interact with a PDP, a process that can be particularly time-consuming for legacy systems.
User Recommendations
  • Investigate the support for externalized authorization, when procuring new applications, using the AuthZEN Authorization API. Just as SAML or OIDC support was essential for authentication, introduce AuthZEN as an optional criterion for authorization from SaaS and COTS vendors to reduce reliance on proprietary systems and vendor lock-in. AuthZEN’s benefits for centralizing control and enhancing security warrant its inclusion in evaluation criteria, albeit as a nice-to-have for the time being.
  • Develop playbooks for integration patterns and potential SDKs for internally developed applications. Stay updated on the OpenID Foundation AuthZEN Working Group’s progress. The working group is defining further mechanisms, protocols and formats, with efforts extending beyond the initial PEP-PDP API.
  • Recognize that AuthZEN standardizes the PEP-PDP request/response but not the authorization model or policy language. Choose a PDP based on your preferred model.
Gartner Recommended Reading

Identity Visibility and Intelligence Platforms

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Identity visibility and intelligence platforms are products that provide rapid integration and visibility for identity and access management (IAM) relevant data, typically paired with advanced analytics (often AI-enabled) capabilities. This innovation provides a single view of IAM data, activity/events, relationships, configuration and posture to enable rapid improvement of all other integrated IAM controls and capabilities supporting both improved security and business enablement.
Why This Is Important
Even with mature IGA, AM and PAM solutions, many organizations struggle to achieve full visibility (“single pane of glass”) in a reasonable timeline and at sustainable cost. The typical organization is still only partly integrated for IAM needs after years of investment and effort. Identity visibility and intelligence platforms enable substantially more rapid and comprehensive visibility and observability, further enabling improved intelligence leveraging the consolidated IAM data.
Business Impact
Identity visibility and intelligence platforms can significantly accelerate visibility into and discovery of IAM data, events, configuration and posture providing faster, less expensive “single pane of glass” view into all access for all actors in an organization. In turn, this enables both better IAM risk/posture assessment and recommendations, and more rapid identification of enhancements to improve business enablement and user experience.
Drivers
  • The vast majority of IAM programs have a high priority for and target of full visibility, since managing or making improvements to any area with blind spots is not possible. This is explained simply with the visibility, intelligence, action (VIA) model which makes clear that all action quality is dependent on quality of intelligence, which is further dependent on degree of visibility (including data quality).
  • Purchase and implementation of leading IGA, AM and PAM solutions have not, by themselves, enabled most IAM programs to achieve desired levels of visibility in the expected time and at sustainable cost.
  • While many IAM leaders are aware of the value of advanced analytics including AI enabled IAM analytics, the optimal architecture to achieve maximum value from analytics is connected to a single component/system, which has comprehensive visibility (vs. siloed visibility and analytics which deliver more limited value).
  • The availability of more flexible and more relational data architectures, specifically graph data stores, makes higher visibility “fidelity” with actual access configuration more easily achievable than tooling built on relational databases.
  • There is remaining, unmet demand for greater automation of IAM for both security and business enablement objectives, but automation design remains a high level of effort and high sustaining cost process without strong visibility and intelligence supporting these automation efforts.
Obstacles
  • IAM program budgets are typically constrained, especially with existing investments in IAM tooling. Many organizations will find it hard to justify extra spending on what is often viewed as supplemental rather than foundational IAM component/capability.
  • Most vendors with relevant tooling are focusing sales on specific action layer scopes such as improving IGA, ITDR or IAM posture/hygiene. This diversity of action layer focus may confuse the market and reduce the perceived value of comprehensive visibility and intelligence.
  • Overall market recognition of the importance of good data management practices for IAM success is low. Therefore, adoption/use of this type of tool is not yet required/expected as a standard practice.
  • Existing IAM data management practices are low maturity on average, creating obstacles to effective adoption and implementation of leading visibility and intelligence capabilities.
  • Legacy applications (not API-enabled) remain more challenging to integrate than modern applications, though some vendors offer solutions for legacy application integration as well.
User Recommendations
  • Formally assess your current IAM technology portfolio for its ability to provide required visibility including ease/speed of integration and ability to retain full visibility for highly relational datasets.
  • Assess and document (using outcome-driven metrics) the impact of visibility and intelligence gaps on your target outcomes for security and business enablement, then use this assessment to justify further investment.
  • For organizations lagging in required levels of visibility and data integration with existing IAM toolsets, explore and evaluate identity visibility and intelligence platform vendors for potential value as an addition to your identity fabric.
  • For organizations lacking a formal IAM data management process, begin with establishing good IAM data engineering and management practices including planning for an analytical data foundation (IAM data warehouse or data lake as appropriate).
Sample Vendors
AKA Identity; AuthMind; Axonius; Elimity; Nexis; Oleria; Radiant Logic; SGNL; Silverfort; Veza
Gartner Recommended Reading

RISC

Analysis By: Felix Gaehtgens
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Embryonic
Definition:
The OpenID Risk Incident Sharing and Coordination (RISC) profile specification from the OpenID Foundation’s Shared Signals Working Group enables the sharing of risk and incident information between different parties within the identity and cybersecurity ecosystems. It aims to improve security by enabling collaboration between organizations to exchange real-time risk and incident data about accounts and credentials in order to mitigate threats effectively.
Why This Is Important
Exchanging real-time security signals about user account and credential state changes (such as lockout, password reset, credential change, etc.) is crucial for improving security. RISC enables providers to reduce the risk of attackers compromising linked accounts, and coordinate in the event of compromise. It complements Continuous Access Evaluation Protocol (CAEP), which focuses on session management. Together, they enable collaborative threat intelligence by sharing security signals that can detect and prevent attacks.
Business Impact
Sharing security signals about user account and credential state changes helps organizations collectively defend against common threats such as account takeover (ATO). An example of this is when a social media account is targeted, breached and then used to take over other linked accounts and services. It also helps organizations adopt a better zero-trust approach by enabling the continuous assessment of risk. Ultimately, it helps defend better against common threats and mitigate the impact on affected systems and users.
Drivers
  • Credential hijacking and other ATO attacks are major persistent threats, with attackers constantly updating their tactics.
  • Federated sign-on and account linking is commonplace for B2C scenarios, where customers link their accounts with large platform providers or social media to sign on to other providers’ sites. Compromise of these accounts thus allows attackers to access these other services.
  • Identity theft is a persistent problem and has been growing, driven by the sophistication of tactics employed by cybercriminals, the increasing proliferation of online services and the increasing digitalization of personal information.
  • There is no other current industry standard to help prevent ATO and online fraud, although there are different proprietary vendor solutions.
  • Examples of large-scale deployments include Google, which provides a cross-account protection feature based on RISC, and the U.S. General Services Administration’s Login.gov, which uses RISC to enable partners and replying parties to notify them of various security-related events.
Obstacles
  • At time of writing, there are few commercial implementations of RISC.
  • Security events exchanged using RISC can contain personally identifiable information in the form of an email address or a phone number to identify accounts or identifiers. The specification already contains features for users to opt out of RISC events sent for their accounts, although additional privacy constraints may arise.
  • The RISC framework defines the signals that can be exchanged between organizations. However, there is no specification or proposal on how to scale the exchange of signals between multiple different organizations in a many-to-many type relationship.
User Recommendations
  • Start implementing CAEP first, as it currently has more vendor support, then consider implementing RISC.
  • Plan to exchange risk signals for account takeover risks in the medium term by assessing which capabilities and tools are in scope and cataloging the types of risk signals they can support and consume. RISC currently supports 15 signals such as “identifier changed,” “credential compromise,” “account recovery activated” and “account credential change required.”
  • Use Google’s cross-account protection feature to enhance security for those users who register and sign on with Google Accounts.
  • Learn from experiences in similar and related areas. If your organization participates in threat intelligence sharing, reach out to the respective teams to acquire knowledge.
  • Plan for a transition period with mostly proprietary signaling frameworks by scanning the market for and implementing products offering protocol translation.
  • Discuss plans with vendors for supporting RISC and check their roadmaps for future support to plan adoption.
Sample Vendors
Google; ID.me; SGNL; U.S. General Services Administration
Gartner Recommended Reading

Deepfake Detection in Meeting Solutions

Analysis By: Akif Khan, Nayara Sangiorgio
Benefit Rating: Moderate
Market Penetration: Less than 1% of target audience
Maturity: Emerging
Definition:
Attackers are using synthetic/deepfake audio or video content within calls on enterprise meeting solutions platforms such as Cisco Webex, Google Meet, Microsoft Teams or Zoom to target employees. Real-time deepfake detection solutions join calls to analyze the audio and/or video content and alert participants to a possible attack.
Why This Is Important
Attackers can now easily create deepfake content. Only a few minutes of reference audio is needed to create a deepfake voice of a target. Creating convincing deepfake video of a target’s face is more complex, but achievable. Attackers can target executives at organizations and use deepfakes of them combined with social engineering to call employees with the intent of tricking them into carrying out malicious actions or subvert account recovery workflows. They can also join board meetings to carry out industrial espionage.
Business Impact
Deepfake technology is proving to be a threat to organizations. In 2024, a global company was tricked out of $25 million dollars using an engineered presence of the company’s CFO. This is one of several reported examples of attackers using these techniques to trick employees into making large fund transfers. Defense against such attacks critically depends on the human factor, but employees are susceptible to social engineering when they believe they are speaking to senior executives. Other use cases involve attacks on the IT help desk to subvert account recovery workflows, or executive impersonation to join board calls to steal sensitive information.
Drivers
  • The barriers to use for tools that can enable the creation of deepfake audio and video continue to drop.
  • Social engineering as an attack vector is a problem with no easy solutions, and it remains a highly effective exploit. Its use in attacks on organizations continues to increase, representing a persistent risk to corporate cybersecurity.
  • Enterprise meeting solutions platforms such as Cisco Webex, Google Meet, Microsoft Teams or Zoom do not offer natively integrated deepfake detection.
  • A growing number of start-up vendors have introduced products in which bots join calls as a participant on an enterprise meeting solution platform to access the audio and videostream. They then provide real-time alerts to the presence of deepfake audio or video content in the meeting.
Obstacles
  • The technology is unproven at scale. The vendors in this space are all nascent; many are still seeking funding, while others are at a point of working with design partners and running proofs of concept (POCs).
  • The scale of the threat remains unquantified. While some high-profile attacks have been reported in the media, there is no data revealing how widespread an issue this really is for organizations. This makes it hard for security leaders to justify investment amid competing priorities.
  • Deepfake detection solutions potentially risk large-scale operational disruption to a business if employees don’t have clear remediation guidance, and are leaving calls when alerted to deepfakes or attempting inappropriate verification. The problem would be exacerbated by inevitable false positives.
  • Current solutions do not protect all platforms. While enterprise meeting solutions platforms could be protected, attackers could still contact employees via WhatApp, FaceTime or even direct phone calls. Alternative layers of protection will still be needed.
User Recommendations
  • Assess emerging deepfake detection solutions for enterprise meeting solutions with the mindset of being an early adopter. Run small-scale POCs and test whether such detection can be operationalized with minimal business impact.
  • Recognize that deepfake detection alone will not solve this challenge, nor protect all channels.
  • Ensure that employees are educated and trained to recognize and resist social engineering using vendors who specialize in deepfake red teaming.
  • Develop playbooks to prepare employees to respond when alerted to the possible presence of a deepfake in an online meeting.
  • Audit business processes to learn which ones are most vulnerable to social engineering involving deepfakes. Add additional authorization steps such that a single online meeting cannot be the trigger for a catastrophic event.
  • Implement processes that enable an employee to authenticate themselves when required. For example, use phishing-resistant multifactor authentication to log into finance applications and authorize large money movements.
  • Use identity verification for account recovery workflows where authentication cannot be carried out.
Sample Vendors
Beyond Identity; DeepTrust; GetReal; Netarx; Reality Defender; Resemble AI; Truly
Gartner Recommended Reading

Workload Identity Management

Analysis By: Steve Wessels, Erik Wahlstrom
Benefit Rating: High
Market Penetration: More than 50% of target audience
Maturity: Emerging
Definition:
Workload identity management tools provide visibility of workload identities, essential for security and mitigating risk. By implementing continuous discovery, organizations can ensure that workload identities comply with company policies. This includes capabilities for discovering, monitoring, managing and administering workload identities, accounts, credential use and the access policies associated with them.
Why This Is Important
The proliferation of workload identities used by virtual machines (VMs), containers, services and applications, have outpaced human identity growth by an order of magnitude, creating new operational and security risks. Traditional identity and access management (IAM) solutions are insufficient to manage modern workload identities and access. Workload identity management has emerged as a critical practice to manage identities, credentials and access permissions for machine identities, ensuring visibility into machine-to-machine interactions.
Business Impact
Workload identity management tools provide insights into the existence and security posture of machine identities, enhancing visibility and enabling proactive management. They offer remediation technologies, security posture assessment, and help in root-cause analysis and ownership assignment. These tools are especially useful to manage legacy credentials such as service accounts and API keys that tend to be difficult to manage long term, thus fostering a more resilient business environment.
Drivers
  • Security and compliance pressures: Rising regulatory requirements demand stronger controls over workload authentication and credential management.
  • Lack of visibility and guidance: Leads to an unstructured, opaque situation where many teams create workload accounts with little governance or oversight, leading to security vulnerabilities.
  • Operational resilience: Expired certificates, unmanaged secrets and poor visibility into machine-to-machine authentication are leading causes of service outages and security incidents.
  • Cloud and DevOps enablement: Highly automated environments require seamless integration with continuous integration/continuous delivery (CI/CD) pipelines, Kubernetes, service meshes and cloud-native platforms, necessitating life cycle automation for workload credentials.
  • Third-party risk: Third-party workloads accessing enterprise systems, typically operate with privileged access but remain inadequately monitored and managed.
  • Risk reduction and governance: Centralized discovery, monitoring and policy enforcement for workload identities reduce the attack surface and support Zero Trust initiatives.
  • Crypto-agility requirements: Discovery and visibility of all types of credentials enables migration to postquantum cryptography.
Obstacles
  • Diverse workload Identities: Different workloads use varying credentials, requiring distinct tools and processes, complicating unified management for the vendors. A range of tools is needed to meet workload requirements.
  • Lack of standardized integrations: Without standardized protocols for discovering and managing workload identities, unique APIs for each application and service slow development as vendors create specific plugins.
  • Legacy culture: Many teams and stakeholders understand and default to the legacy service account model and are unaware of modern machine identity practices, perpetuating legacy practices.
  • Privileged access requirements: Workload identity management tools require view and administrative rights across systems, posing security challenges for CISOs in balancing operational needs.
  • Modern workload access management: New workload deployments use dynamic service identities and just-in-time access with short-lived tokens, making it important to not manage and control each account and credential, but instead ensure that all systems adhere to organizational policies.
User Recommendations
  • Add teams, processes and controls to ensure that workload identities are managed in your hybrid and multicloud environment.
  • Establish a cross-functional working group to lead the transformation to a modern workload identity management practice.
  • Conduct continuous discovery and assessment to identify workloads needing management and control. Enhance observability by collecting and correlating data from diverse sources.
  • Catalog out-of-compliance systems and establish, automated if possible, otherwise manual, life cycle management processes.
  • Enable developer empowerment with self-service interfaces and code libraries to stop the bleeding.
  • Implement dynamic service identities using platform provided identities or SPIFFE in conjunction with access tokens for secure workload communication.
Sample Vendors
Akeyless; Astrix Security; Clutch Security; CyberArk; Entro Security; GitGuardian; Natoma; Oasis Security; Token Security
Gartner Recommended Reading

Policy as Code

Analysis By: Paul Delory
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Policy as code (PaC) languages express governance and compliance rules as code, so they can be enforced programmatically by automation tools. PaC languages are often domain-specific and declarative. With PaC, policies are treated as software, making them subject to version control, code review and functional testing. The most mature PaC tools can render any business logic in code. You can use PaC today to enforce infrastructure compliance, authorization, Kubernetes admission control and more.
Why This Is Important
Platform engineers use PaC to build optimization, governance and compliance controls into automation pipelines. Infrastructure and security teams have used it for years to build guardrails around infrastructure and data while preserving a separation of duties that mirrors a typical IT organization chart. With the rise of generative AI (GenAI), PaC is poised to become a way to control AI agent behavior and enforce standards programmatically, which current GenAI tools often struggle to do.
Business Impact
  • Security, compliance and automation: PaC, combined with automation, enforces policies with implicit compliance guarantees.
  • Alignment of security and operations teams: PaC allows security and compliance teams to interface directly with automation pipelines.
  • Visibility and auditability: PaC documents policies. PaC tool logs can be audited to prove policies are being enforced.
  • Time and effort spent: PaC means less toil for operators because it forestalls configuration drift and out-of-spec elements.
Drivers
  • Emerging standard: Several dedicated PaC tools are now on the market, many of them open source. The Open Policy Agent (OPA), a Cloud Native Computing Foundation project, has become the de facto standard for PaC. Even some other PaC tools now use OPA policies alongside or instead of their own policy engines.
  • Increasing regulations: Regulations such as General Data Protection Regulation have increased both the difficulty of compliance and the pressure on compliance teams. PaC allows compliance teams and auditors to document their policies in detail and verify that they are being enforced.
  • Agentic AI: The advent of GenAI agents is transformational across almost every industry, but organizations struggle to control the behavior of AI agents. PaC can provide both effective control and meaningful testing and auditing of agents’ outputs.
  • Security breaches: A spate of newsworthy security breaches at public companies — caused by infrastructure misconfigurations — has put every IT organization’s security and compliance practices under increased scrutiny. No infrastructure and operations team wants its security failures to be the reason its company gets negative headlines.
  • Continued growth of DevOps and DevSecOps: As more companies are embracing DevOps and DevSecOps, they are also encountering the hard governance problems of automation. Many teams that implement infrastructure as code quickly find that they need better policy enforcement, and PaC can help.
  • Cloud optimization and cost control: Besides their benefits for security and compliance, PaC tools can also be used to enforce the build standards for infrastructure, including budgets. In the public cloud, where oversized or unnecessary infrastructure incurs direct out-of-pocket costs, programmatically enforced policies can help to control spending.
Obstacles
  • Scarcity of downloadable content: PaC tools will not gain real traction until they have extensive libraries of community-generated content from which users can download the policies they need rather than having to write their own. Over time, as the user base expands, PaC tools will reach a critical mass of downloadable content that supports real-world uses.
  • Skill set: Many technical professionals lack the skills to operate automation and PaC tools effectively. As the learning curve might be steep for some, you may need to accept some flubbed policy enforcement due to lack of experience.
  • Integration challenges: Integrating with existing tools is complex and often requires additional configuration.
  • Organizational inertia: In some organizations, collaboration between infrastructure and operations teams and security or compliance teams is actually unwanted. This dynamic may slow the rate, scope and scale of PaC initiatives.
  • Costs: Even if PaC tools themselves are free, you may still require training or consulting.
User Recommendations
  • Start small: Choose a pilot use case where PaC will likely provide real business benefits, then expand to others once PaC has proven its value.
  • Upskill staff: PaC languages are not always intuitive. Technical staff will need practice and/or training. Adopt the four-eyes principle to prevent flawed policies from impacting operations.
  • Promote reusability: Focus your PaC efforts on use cases that have ready-made implementation templates — ideally, downloadable content. For example, almost every PaC tool on the market has a canned implementation of the customer information systems benchmarks.
  • Break down team silos: Use PaC to build a common workflow for automation and policy enforcement that spans platform engineering, infrastructure and operations, security, and compliance teams.
  • Integrate PaC into automation pipelines: Use PaC to build guardrails for automation tools, so that they cannot take actions that are out of compliance.
  • Measure before and after: Use observability tools and value stream mapping to define your starting state, then compare it to the end state. Collect real data to quantify the value of PaC.
Sample Vendors
IBM (HashiCorp); Palo Alto Networks; Progress; Pulumi; Styra
Gartner Recommended Reading

AI for Access Administration

Analysis By: Nathan Harris
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
Artificial intelligence (AI) for access administration is the application of all types of AI (machine learning, generative AI [GenAI] and agentic AI) specifically for access governance and administration. Common applications are rapidly and efficiently identifying and resolving instances of excess access (least privilege violations) and not enough access (justified access that isn’t provisioned), including proposing rules to standardize, automate and govern entitlements.
Why This Is Important
Nearly all organizations find it difficult to manage access effectively, even if they have implemented identity governance and administration (IGA) tooling. Ever-changing workforce populations, business applications and IT systems, combined with no standard approach for entitlements/permissions models in apps and systems, make keeping up with effective access policies nearly impossible. AI methods can help improve manageability, sustainability and overall progress of target outcomes for access administration.
Business Impact
Applying AI to access administration (including access governance) processes can reduce manual work, improve delegation to non IAM teams, and speed up value delivery for identity and access management (IAM) teams struggling to keep up with organization changes and transformation. Using AI for access administration enables more rapid improvement in access policy than is possible with human decision making alone. This can improve IAM program results for business enablement, security and compliance simultaneously.
Drivers
  • Even with access administration and governance automation tooling (pre-AI), identifying and configuring rules/policies to address both least-privilege issues and access provisioning automation needs is simply too much work for most IAM programs. Applying access policy may be automated, but analyzing, modeling and configuring policies remain manual in most organizations.
  • Rapid advancement in AI capabilities, including (but not limited to) GenAI and agentic AI, makes AI more capable of processing high data volumes of access in most organizations. This can also deliver recommendations for access policy improvements (access modeling) more quickly and responsively to organization and IT system changes.
  • Most IAM programs have a security mandate to keep assigned access well-maintained and as close to the least-privilege principle as possible. Many successfully address access termination when an individual leaves the organization, but most are unable to successfully maintain good access hygiene overall, especially related to mover/transfer activity, even when using leading IGA tooling. AI for access administration enables faster response to changes and identification of hygiene issues to be addressed.
  • Most IAM programs also have a business enablement mandate to grant access that is justified as quickly as possible (right-time access). This enables their business to operate effectively, yet progress on the automation to accomplish this is slow in most organizations, with little to no “sight line” to fully achieving target outcomes. Applying AI can accelerate access automation efforts.
  • Lack of standards for how entitlements and permissions are managed across different systems prevents the IAM team, which has figured out how to standardize access for one system, from immediately applying to the next system. The sheer amount of access modeling and analysis needed is beyond the delivery capacity of most real-world IAM teams, but not beyond the capacity of AI methods.
Obstacles
  • Machine intelligence is no better than human intelligence at dealing with data that doesn’t exist. As a result, the value of AI to access administration in each organization will be limited to use cases where the organization can provide the necessary identity, entitlement and access event data to drive AI models. Organizations need to make improvements in IAM data management to realize full value from this innovation.
  • All AI is probabilistic rather than deterministic. It will not be able to recommend the right access for 100% of client use cases. Highly risk- and compliance-sensitive organizations may have difficulty getting to an acceptable comfort level with AI recommendations for access policies and decisions.
  • AI implementation is still expensive and complex, including model selection per use case, necessary tuning, and requirements to address trust, risk and security management (TRiSM). While capability is rapidly improving, the cost of entry to this capability for vendors and client companies remains high.
User Recommendations
  • Ask for AI-driven access administration capabilities from your IGA vendors. When this is not available, evaluate supplemental solutions.
  • Improve data management/engineering capability of IAM programs to improve both manual access administration and AI-facilitated access administration.
  • Test and implement AI-driven access administration improvements from IAM vendors. Evaluate the outcome primarily on its impact on the speed of delivering process improvements (do not expect 100% accuracy).
  • Expect technology vendors, including, but not limited to, IGA vendors, to incorporate AI methods and models into their solutions to help customers get more rapid and sustainable value. Use best-available AI models to improve both access provisioning/deprovisioning processes and access review/certification processes.
Sample Vendors
Delinea; Gurucul; IBM; Lumos; Nexis; Ping Identity (ForgeRock); Radiant Logic; SailPoint Technologies; Saviynt; Veza
Gartner Recommended Reading

At the Peak

SPIFFE

Analysis By: Felix Gaehtgens
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Secure Production Identity Framework for Everyone (SPIFFE) defines a set of specifications to securely identify and authenticate services in dynamic and heterogeneous environments. It aims to provide a consistent, infrastructure-agnostic approach to service identity management, enabling secure service-to-service communication in cloud-native and distributed systems. SPIFFE decouples service identity from underlying infrastructure, enhancing security, scalability and interoperability.
Why This Is Important
SPIFFE aims to solve the hard problem of securely identifying workloads in distributed systems. This enables organizations to move away from a model based on service accounts with static credentials or shared secrets (legacy practices). These legacy practices have a high overhead because they require administration of account life cycles, and are also less secure and less flexible because they often rely on static and shared credentials.
Business Impact
SPIFFE positively impacts organizations deploying AI agents, APIs or IT infrastructures with automated processes. It enhances security in service-to-service interactions through credentialing and authentication, addressing vulnerabilities inherent in static credential use by eliminating the need for workloads to store credentials. SPIFFE provides a secure-by-design approach, offering flexibility and agility in deploying new infrastructure and services.
Drivers
  • Organizations on the way to implementing zero-trust security must deal with the difficult problem of credentialing and authenticating machine-to-machine interactions, which SPIFFE addresses.
  • Both SPIFFE (the framework) and Spire (an open-source implementation of SPIFFE) are projects from the Cloud Native Computing Foundation (CNCF) with “graduated” status, indicating their maturity. This helps SPIFFE’s adoption in cloud-native infrastructure, especially Kubernetes, OpenShift and derivatives.
  • The boom in AI agents requires careful consideration of how AI interactions are secured. SPIFFE provides an elegant solution to address one major part of this problem: bootstrapping identity, that is, securely identifying and issuing a credential to a workload.
  • Google Cloud Platform (GCP) is using SPIFFE to underpin its managed service identities.
  • Microsoft has documented integration between SPIFFE and workload identity federation features of Entra ID.
  • SPIFFE offers more granular control over identity issuance than the model of using managed service accounts. SPIFFE can issue a credential to an individual process, whereas managed service accounts tend to project the credential to the entire container, which would require additional mitigation to ensure that unauthorized processes do not access it.
  • Several vendors in the PAM and machine IAM spaces have started offering SPIFFE support in their products, enabling applications to access their tools with a SPIFFE-issued credential that can either be an X.509 certificate or a JSON Web Token.
  • Use of SPIFFE reduces operational complexity that would otherwise be generated by use of legacy service account practices.
  • Use of SPIFFE helps accelerate development and deployment because developers can focus more on writing application logic and less on managing credentialing and authentication in distributed systems.
Obstacles
  • Culture shift: While SPIFFE is a key enabler of a zero-trust security model for workload identities, it requires a change in mindset and practices across development, operations, security and IAM teams that are accustomed to legacy practices.
  • Integration with existing infrastructure: SPIFFE works great for new deployments, but integrating it with the diverse heterogeneous landscape found in most organizations can face challenges. Although multiple integration patterns exist, they sometimes require supplemental components such as proxy servers, service meshes or secrets managers.
  • Skills: SPIFFE requires expertise in areas such as public key infrastructure (PKI), cryptography and distributed systems. Credentials issued by SPIFFE rely on workload attestation, that is, the process of verifying the identity of a workload at runtime, which must be planned carefully.
User Recommendations
  • Build expertise: SPIFFE and its underlying concept of workload attestation are likely new and a departure from legacy service account models. Invest in knowledge sharing and prototyping to build internal expertise and develop internal champions that can help others.
  • Integrate with other systems: SPIFFE integrates well with existing security infrastructure, such as PKI, secrets managers and service meshes. However, integrating with existing applications may require additional patterns and tools.
  • Extend reach: Use SPIFFE in combination with workload identity federation to extend the trust of SPIFFE credentials outside your domain.
  • Achieve observability: Ensure that SPIFFE events and logs integrate into, and correlate with, monitoring and logging tools to achieve observability.
  • Integrate with authorization systems: SPIFFE focuses on authentication, that is, verifying the identity of a workload. However, workloads also need authorization, which SPIFFE does not cover. Yet, SPIFFE does provide some of the critical information that an authorization service can use to make decisions.
Sample Vendors
Cloud Native Computing Foundation; Google; SPIRL
Gartner Recommended Reading

CAEP

Analysis By: Erik Wahlstrom
Benefit Rating: High
Market Penetration: 1% to 5% of target audience
Maturity: Emerging
Definition:
The Continuous Access Evaluation Profile (CAEP) of the Shared Signals and Events (SSE) Framework defines mechanisms to communicate security events between trusted parties to enable continuous runtime access decisions. CAEP is a standard that enables identity and access management (IAM), security tools, and the applications and services they protect to continually share security signals to enable session management, mitigate breaches and reinforce policies in a decentralized environment.
Why This Is Important
  • Single sign-on is well-established in organizations’ hybrid environments, but single logout and continuous session management have been elusive so far.
  • Sharing risk events between tools and applications is essential for an interconnected world built on distributed trust.
  • CAEP helps resolve challenges with long-token lifetimes, step-up authentication, the continuous assessment of assurance levels and device postures. It also provides mechanisms to help address identity life cycle events.
Business Impact
Sharing security signals (CAEP events) increases security in loosely connected services and enables continuous control, higher assurance levels, and a better user experience across a hybrid and decentralized IT environment. Leveraging CAEP events as a response to changes or detected threats enables applications and IAM tools to take actions such as termination of a session, reevaluation of claims, step-up authentication, and management of user and entitlement life cycle.
Drivers
  • Modern IAM requires event-based and runtime communication mechanisms to evaluate and establish trust, and orchestrates the right tools for the use cases. For example, an event that says a user is no longer valid or a device’s out-of-compliance security posture must trigger other IAM tools to respond to that event, manage affected identities and reevaluate access decisions in runtime.
  • The increasing decentralization of applications and services in organizations’ hybrid and multicloud environments makes continuous session management imperative but hard or impossible to achieve. For example, single logout integrations have historically been impossible to deploy at scale.
  • Organizations need continuous adaptive trust (CAT) and an interoperable way to react to risk events that happen during sessions to understand what’s going on in applications after users are authenticated. At scale, this can only be achieved using identity standards like CAEP.
  • Using CAEP to continuously feed signals into an adaptive access engine enables the engine to have more data and thereby make more accurate access decisions.
  • The IAM community is starting to implement CAEP. There are 20+ implementations, where a handful are generally available.
  • Gartner, together with the OpenID Foundation, hosted three successful interoperability sessions with 19 CAEP implementations at the Gartner IAM Summit during 2024 and 2025, showing the protocols’ utility, interoperability and implementability (see Gartner Identity & Access Management Summit). During and after the sessions, Gartner clients emphasized the importance of this unmet market need.
Obstacles
  • CAEP is still not commonly known and understood by IAM professionals, or application and service developers.
  • Although implementation has started, all identity standards take a long time to be commonly implemented. Identity standards have a “chicken and egg” problem before they reach wide deployment. Target applications wait to see if a standard takes off, and IAM vendors wait for wide support in their target applications. This is also true for CAEP. The number of implementers is growing but still from small numbers.
  • Another implication of the slow market saturation of new identity standards is the market need for tooling that can help modernize legacy tools and integrations by brokering and translating CAEP events to nonsupporting environments. Gartner is only aware of two such brokers at the moment: SGLN and IBM.
User Recommendations
  • Define an IAM architecture that supports centralized control in a decentralized environment by embracing open standards. CAEP complements other modern identity protocols such as OpenID Connect, System for Cross-Domain Identity Management (SCIM), JSON Web Tokens (JWTs) that enable it.
  • Require IAM vendors to support CAEP. Gartner expects CAEP and other related standards to share security and risk events across decentralized systems to become increasingly important going forward. For example, the SCIM Events and Risk Incident Sharing and Coordination (RISC) profiles of the OpenID SSE Framework specification.
  • Add CAEP as an optional RFP criterion when procuring new applications, specifically SaaS apps. Support is still emerging, but Gartner expects the adoption of CAEP to grow. Configuring a new application in an IAM tool should, over time, include standardized life cycle management, single sign-on and event sharing.
Sample Vendors
Apple; Cisco; Google; IBM; Jamf; Okta; Omnissa; SailPoint; SGNL; Thales
Gartner Recommended Reading

Cybersecurity AI Assistants

Analysis By: Jeremy D'Hoinne
Benefit Rating: Moderate
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Cybersecurity AI assistants leverage generative AI techniques to discover existing knowledge available from cybersecurity tools, generate content or code, and assist security teams in their daily tasks. Cybersecurity AI assistants are mostly available as companion features in existing products, but can also take the form of a dedicated front end and can integrate software agents to take action.
Why This Is Important
Most cybersecurity technology providers are now embedding a generative AI (GenAI) assistant into their existing products. These cybersecurity AI assistants deliver knowledge discovery and content creation (often as summarization or generated code/script). Their promise of improved productivity appeals to cybersecurity executives. These assistants are slowly evolving to be multimodal and agentic, which means they can be used to assemble automations to complete repetitive tasks across multiple cybersecurity tools.
Business Impact
  • Organizations use cybersecurity AI assistants as part of their existing tools and conduct pilots with standalone AI assistants.
  • Cybersecurity can improve operator accuracy resulting in lower business downtime and potentially less data loss due to security incidents.
  • Organizations with high cybersecurity administrative turnover benefit from shorter training periods due to the advantages of these assistants.
  • Cybersecurity AI assistants can help implement more secure code, fix cloud misconfigurations, generate scripts and code, and identify key security events in logging systems.
  • Other use cases for cybersecurity AI assistants include the tuning of security configuration adjustment, and conducting risk and compliance identification and analysis.
Drivers
  • The biggest driver of adoption is the vast availability of generative AI tools and frameworks, leading to a fast adoption by providers.
  • Cybersecurity AI assistants help teams to quickly create general best-practice guidance, synthesize and analyze threat intelligence, automate the first steps in incident response, and generate remediation suggestions for application security.
  • Organizations continue to experience skill shortages and look for opportunities to automate resource-intensive cybersecurity tasks.
  • Cyber risk analysts need to speed up cyber risk assessments, and be more agile and adaptable through increased automation and prepopulation of risk data in context.
  • More broadly, GenAI might augment existing continuous threat exposure management programs by better aggregating, analyzing and prioritizing inputs. It can also generate realistic scenarios for validation.
Obstacles
  • Uncertainty about the pricing of these assistants will play a big factor in the pace of adoption. Today, only a few providers have communicated about their pricing, while many give early previews for free.
  • The cybersecurity industry is already plagued with false positives. One bad “hallucination” or an inaccurate response by GenAI will cause organizations to be cautious about adoption or limit the scope of their usage.
  • Best practices and tooling to implement responsible AI, privacy, trust, security and safety for GenAI applications do not fully exist yet. Security teams might be reluctant to enable GenAI features without guarantees regarding the security and privacy of their data.
  • The scope of cybersecurity AI assistants is often limited to the product they are part of, creating fragmentation of insights and limiting their value.
  • Organizations still require the core skill sets they are supposed to augment using GenAI. Currently, adopting GenAI will likely increase workloads before it successfully decreases them.
  • As GenAI is still developing, establishing the trust required for its wider adoption will take time. This is especially true for the skill augmentation use cases, as you would need the skills you are supposed to augment in order to ensure that the recommendations are good.
User Recommendations
  • Build AI literacy and develop metrics to measure the success of the pilot program.
  • Be sure to have a control group to validate improvements against.
  • Pick initial use cases carefully and advertise them as pilots taking the form of an integrated feature of existing tools or stand-alone products that do not replace existing tools.
  • Monitor the addition of GenAI assistants from your existing providers and beware of GenAI washing. Don’t pay a premium before obtaining measurable results.
  • Evaluate privacy features and the model architecture to ensure the security of data shared with the GenAI assistant.
  • Implement a documented approval workflow for allowing new generative cybersecurity AI experiments to avoid the unmanaged sharing of sensitive data.
  • Implement a policy requiring that any content (that is, configuration or code) generated by an AI is fully documented, peer-reviewed by humans and tested before it is implemented. Otherwise, consider any AI-generated content as “draft only” when used for critical use cases.
Gartner Recommended Reading

AI-Augmented Software Engineering

Analysis By: Arun Batchu, Manjunath Bhat, Nitish Tyagi, Keith Holloway
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
AI-augmented software engineering (AIASE) refers to the integration of AI as a collaborative partner to enhance the capabilities of software engineers across the software development life cycle (SDLC). It aims to accelerate the delivery of high-quality software by leveraging AI technologies in various phases, including planning, design, development, testing, validation, security, deployment and maintaining applications.
Why This Is Important
The SDLC encompasses routine tasks within both the creative and operational DevSecOps loops. AI automation reduces manual effort, allowing engineers to focus on innovation, reduce technical debt, enhance quality and security, improve team collaboration, and lower operational costs. AI technologies augment engineers’ cognitive tasks, including analyzing logs, optimizing configurations and generating scripts, code, unit tests and documentation.
Business Impact
AIASE transforms the SDLC by integrating AI as a collaborative partner. This integration accelerates the delivery of high-quality software and enhances various phases of development, including planning, design, testing and maintenance. By automating routine tasks and augmenting cognitive tasks such as log analysis and code generation, AIASE reduces manual effort, allowing engineers to focus on innovation. This leads to reduced technical debt, improved quality and security, enhanced team collaboration and lower operational costs, ultimately providing transformational benefits to organizations.
Drivers
Demand-side drivers include:
  • Increased complexity of software systems to be engineered
  • Increased demand for developers to deliver high-quality code faster
  • Increased number of quality-related risks associated with software development
  • The need to protect against increasingly sophisticated security threats
  • The need to optimize operational costs
Supply-side drivers:
  • Applying AI models to improve software quality by detecting defects, and fixing them
  • Increasing impact of software development on business
  • Applying foundation models such as large language models (LLMs) to software code generation and optimization
  • Applying deep learning models to software operations
Obstacles
  • The 2024 Gartner Technical Architect Survey highlights a growing skills gap in AI/ML, with 31% reporting high demand but persistent shortages across organizations. Top-performing firms increasingly seek software developers with data science skills. And the 2025 Gartner Software Engineering Survey identifies prompt engineering as an emerging skill, underscoring the rising importance and challenge of addressing these skill shortages.
  • Employees fear that job automation by AI will lead to job elimination.
  • The hype surrounding this innovation has led to misconceptions and unrealistic expectations regarding AIASE’s advantages.
  • Myopic focus on code generation has reduced opportunities for AI tool application throughout the SDLC.
  • Solutions are uneven and fragmented, automating only certain tasks within the SDLC.
  • Intellectual property risks and privacy issues arise from AI models trained on restrictive licensed code and proprietary or leaked data.
User Recommendations
  • Pilot tools to assess potential gains, measure their effectiveness, and then roll out or scale them broadly if the results are positive.
  • Innersource best practices, featuring automated prompt generation through saved examples, to effectively use AIASE technology.
  • Validate the accuracy and verify the maintainability of AI-generated artifacts via human or automated reviews.
  • Enter only short-term contracts with vendors to ensure the ability to migrate to more effective tools as the market matures.
  • Ensure psychological safety for software engineers by emphasizing that AIASE serves as a learning partner and augmentation toolset, supporting rather than replacing human expertise, and offering continued career development opportunities.
  • Establish guidelines to choose providers that offer transparency in training data and model processes. Prioritize indemnified commercial models for critical applications, and use tools like SCANOSS for licensing compliance.
  • Establish the correct set of metrics, such as new release frequency and quality artifacts, to measure AIASE’s success.
Sample Vendors
Amazon Web Services; Anima; Atlassian; CAST; Codeium; Dynatrace; GitHub; GitLab; Sedai; Veracode
Gartner Recommended Reading

Sliding into the Trough

Secrets Management Tools

Analysis By: Felix Gaehtgens
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Adolescent
Definition:
Secrets management tools, or “secrets managers,” programmatically issue, store, retrieve, rotate and manage secrets (such as keys, passwords, OAuth client credentials and certificates) for workloads (such as containers, applications, services, scripts, processes and DevOps pipelines). Secrets management tools provide service through APIs, command-line interfaces (CLIs) and software development kits (SDKs). They are delivered as software or as a service and include a secure and encrypted vault.
Why This Is Important
Machine-to-machine communication is widespread, with various workloads like containers, applications, services, functions and AI agents requiring access to sensitive data and infrastructure. Failing to secure this access can lead to — and has led to — security breaches. Workloads use credentials and identifiers that must be protected to prevent exposure. Secrets management tools offer a popular and effective solution for securely issuing and storing these secrets.
Business Impact
Effective secrets management enhances security for transactions, operations and communications between certain nonhuman actors such as workloads. It helps organizations comply with regulations governing the management of identity and access as it applies to machine identities. It mitigates risks of breaches by safeguarding secrets used to implement controls and access restrictions. It also improves operational efficiency by automating the storage, retrieval and rotation of secrets by workloads and DevOps pipelines.
Drivers
  • Threat landscape: Secrets used by workloads often contain privileged entitlements and grant access to critical systems and sensitive data. Unprotected secrets are an easy, lucrative target for cybercriminals. Securing secrets has become a priority, after years of neglect has led to secrets sprawl.
  • Operational efficiency: Managing secrets using manual processes such as storing them in configuration files, or using spreadsheets or workforce password managers, is both inefficient and insecure. Secrets management tools streamline the process of issuing, storing and retrieving secrets. This improves operational efficiency by automating key management tasks and reducing the administrative burden of manual secrets management.
  • Cloud and API adoption: Continuing migration to cloud and hybrid environments requires secrets to be managed across distributed environments, which entails consistent visibility and control over secrets across cloud infrastructure providers, container orchestration systems, APIs and on-premises systems.
  • Machine learning and AI applications: The rise of machine learning and AI applications, which often require access to sensitive data and systems, further underscores the need for effective secrets management to safeguard credentials used by these applications.
  • Regulatory landscape: Many regulatory frameworks mandate protection of sensitive data. When sensitive data is accessed by workloads, its credentials need to be protected. These regulatory frameworks also require the management and protection of cryptographic keys, which can also be secured by secrets management tools.
  • DevOps: The growing adoption and maturity of DevOps requires developers to securely access secrets during the build, deploy and runtime processes. Secrets management tools eliminate the need to store secrets in configuration files or code repositories and integrate with DevOps continuous integration/continuous delivery pipelines to automate build, test, delivery, integration and deployment.
  • Auditability and accountability: Secrets management tools often provide audit logs and monitoring capabilities so organizations can track and monitor the use of secrets. This enhances accountability, facilitates forensic investigations of security incidents and supports compliance audits by providing a clear record of secrets-related activities.
Obstacles
  • Lack of visibility and observability: Organizations struggle to track all credentials and secrets used across their infrastructure due to insufficient discovery and continuous monitoring mechanisms.
  • Vendor lock-in and interoperability: Proprietary APIs and SDKs make it difficult to switch vendors, leading to dependency issues.
  • Fragmentation: Many organizations either use multiple different secrets management solutions or have different needs that call for multiple solutions. Often, individual teams choose their own secrets management tool (commonly provided by communication service providers [CSPs]). This is not a bad practice, but it does require standardization of policies and guidance.
  • Over-reliance on secrets management: Organizations often view secrets management as the single solution for secure workload-to-workload interactions, seeking centralized tools to support all use cases. Apart from vendor lock-in, this inhibits the adoption of a unified strategy for machine identity management and often leads to static credentials that are challenging to manage. A modern strategy should encompass a range of capabilities, including secrets management, but also other methods that better address diverse machine identity and access management scenarios.
  • Pricing: Pricing models and points between different solutions is inconsistent. Native secrets management capabilities offered by CSPs tend to offer the best value for money. Many stand-alone secrets management tools are licensed on a per-client basis, whereby every distinct machine entity requires a yearly subscription fee, often hundreds of dollars. This makes adoption expensive and complicates cost forecasting.
User Recommendations
  • Never store credentials in cleartext: Secrets management tools typically come with a secured vault to protect credentials at rest. However, workloads need to identify themselves to the secrets management tool, often through an authentication mechanism. Never authenticate a workload to a secrets manager using a credential stored at rest within the workload.
  • Consider alternatives: Secrets management is not the only way to secure workload-to-workload access; an alternative may be a combination of platform-issued workload identities and native access policies.
  • Accept fragmentation: Avoid the urge to standardize on one secrets management product to solve all enterprise secrets management needs. This leads to vendor lock-in at significant expense and risks being an imperfect fit for all use cases. Instead, look for vendor features to maintain observability and governance for secrets and platform-managed service identities across multiple tools, vaults and clouds. Start with discovery across multiple secrets management platforms and then expand to cover exposed locations, such as cloud apps, collaboration tools and chats.
Sample Vendors
Akeyless; Amazon Web Services; CyberArk; Doppler; Google; IBM (HashiCorp); Infisical; Microsoft; OpenBao; Segura
Gartner Recommended Reading

IoT Authentication

Analysis By: Michael Kelley
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Internet of Things (IoT) authentication is the mechanism of establishing trust in the identity of an entity (typically a device) interacting with other entities, such as devices, applications, cloud services or gateways operating in an IoT environment. Authentication in IoT takes into account potential resource constraints of IoT devices, the bandwidth limitations of networks they operate within and the automated nature of interaction among various IoT entities.
Why This Is Important
From automotive to smart homes and smart buildings to the smart consumer devices market to industrial IoT (IIoT) and cyber-physical systems (CPS), IoT is expanding as a market. These connected devices can bridge cyber and physical worlds and open up entirely new threat vectors. Among other requirements like encryption and culture, sound IoT security requires a strong identity for IoT devices coupled with strong IoT authentication, with the goal of mitigating and minimizing cyberattacks and vulnerabilities.
Business Impact
IoT authentication can mitigate:
  • Privacy issues that directly impact liability and brand reputation for consumer devices.
  • Attacks against connected devices that could lead to disruption in product or service offerings.
  • Attacks against industrial devices that lead to operational impacts and, potentially, catastrophic events in safety-critical production areas.
IoT authentication is foundational for protection for newer mechanisms in the market, including IoT applications and agentic AI components.
Drivers
  • The explosive growth of IoT and IIoT is creating connectivity between humans and machines and machines to machines in an unprecedented way.
  • Long-term spending growth will be led by automotive (8% compound annual growth rate [CAGR]), manufacturing and natural resources (10% CAGR), and transportation (11% CAGR). Organizations are investing in IoT technologies to drive cost optimization and operational efficiency (see Forecast: Internet of Things, Endpoints and Communications, Worldwide, 2022-2032, 1Q25 Update).
  • Ongoing work for defining secure credential storage and rotation approaches for IoT authentication is helping to drive the market.
  • Many use cases stemming from IoT are changing traditional business models, such as continued developments in telehealth.
  • The popularity of public-key infrastructure (PKI) as an identification approach is helping enable adoption. Certificates continue to be the primary way devices are identified and authenticated. PKI vendor investments and focus in this space include CyberArk (Venafi), DigiCert, Entrust, Keyfactor and Sectigo, leveraging their PKI capabilities to solve IoT authentication use cases.
  • Standards helping to provide consistent approaches and solidifying investments, viability and utility include the Connectivity Standards Alliance’s Matter; RFC 8628, the OAuth 2.0 Device Authorization Grant extension; and the ACE working group within the Internet Engineering Task Force.
Obstacles
  • The IoT landscape is complex, including determining the right people, process and technology to employ due to a fragmented market, with highly industry-specific requirements, and difficulties productizing due to inconsistent device types and operating environments.
  • The fragility of many IIoT environments, including the potential for abuse and catastrophic impact, will drive the continuation of proprietary and isolated approaches for authentication in cyber-physical environments.
  • Some authentication methods are not good candidates due to certain IoT devices that are resource- or feature-constrained with low computing power and limited secure storage capacity.
  • Many organizations have challenges based on the variety of different types of IoT devices in their environment.
  • Support of authentication methods via IoT platforms is immature or incomplete. Use-case areas, such as IIoT, have protocols that are not interoperable with each other and often not operable with standards like TCP/IP, creating ongoing challenges for authentication approaches.
User Recommendations
  • Catalog and establish capabilities for each category of device in its IoT network.
  • Evaluate and adopt authentication frameworks that support the range of device types across the IoT realms in operation.
  • Ensure that policy and process for authentication in IIoT environments continue to prioritize safety over interoperability, including traffic isolation.
  • Use trusted computing techniques, such as hardware root of trust, that help to protect against physical attacks on devices and sensors, as well as against the external software attacks that could enable unauthorized reading, analyzing and manipulating of software code.
  • Educate leadership on the regulatory and privacy risks associated with IoT. Identify use cases where the high cost of people or processes in existing approaches would justify investment in IoT solutions in order to secure funding for tools.
  • Use fusion teams to manage the disparate technical and regulatory requirements of IoT projects and implementations (see Fusion Teams: A Proven Model for Digital Delivery).
Sample Vendors
Akeyless; CyberArk (Venafi); DigiCert; Entrust; IN Groupe (Nexus); Keyfactor; Microsoft; Phosphorus; Sectigo; Xage Security
Gartner Recommended Reading

Machine IAM

Analysis By: Felix Gaehtgens, Erik Wahlstrom
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Adolescent
Definition:
Machine IAM is a practice that expands the scope of IAM to cover the security, integrity and trustworthiness of machine-to-machine interactions. It establishes identity, tracks ownership, and enables trust and observability for workloads (APIs, AI agents, applications and containers) and physical computing devices. It includes issuance and life cycle management for machine identities, policies and credentials, (secrets, keys and certificates) used for identification and authorization.
Why This Is Important
  • Organizations have at least a scale of magnitude more machine identities than human identities, greatly expanding the potential attack surface for threats.
  • Organizations struggle to identify and authorize machines and protect their credentials, leading to leakage and abuse.
  • Machine identity management needs a strong focus on observability, ownership and automation to be able to scale.
  • Machines are used by many different business units within an organization, so a well-aligned strategy with a common set of good practices is needed.
Business Impact
Machine IAM mitigates risks, strengthens security and maintains compliance with regulatory requirements for the organizationsmany machine identities. These machine identities are rarely managed properly, exposing them to risk. Effective management includes issuance of identities and credentials, and life cycle management and access policies. This helps organizations secure communications between workloads and/or devices, required to protect sensitive data, and prevent unauthorized access and cyberthreats.
Drivers
  • Attacks against machine identities are on the rise because hackers see them as “soft targets” that many organizations don’t govern and lockdown properly.
  • The number of machine identities at most organizations is growing rapidly, fueled by the adoption of AI and corresponding AI agents, and cloud infrastructure and modern application architectures such as container orchestration and APIs.
  • Managing machine identities manually is time-consuming and prone to errors, especially in dynamic and large environments.
  • Zero trust requires a strict verification of identities, including for machines. This requires dynamic issuance and life cycle management of credentials, authentication, access control and observability over machine identities, paving the way for dynamic service identities and SPIFFE.
  • Machine identity management is fragmented since there are many types of machines, credentials and identifiers. Each has different needs for automation, issuance and identification. New vendors have entered the space, attempting to resolve problems with the fragmentation by offering centralized governance over fragmented management solutions; however, they often perpetuate legacy service account practices.
Obstacles
  • There are different definitions of nonhuman or machine identities, exacerbated by vendors providing their own interpretation and messaging. This makes selecting the right tooling difficult.
  • Different types and classes of machines, their identities and credentials are managed disparately; it is currently not feasible to manage all machine identities with only one tool. Examples include tools that manage cloud-native identities, cyber-physical system identities, service accounts, secrets and public-key infrastructure.
  • Legacy service account practices are still commonplace, in which accounts need to be managed separately from the workloads that use them. This leads to management overhead and lack of accountability. Workload identity management tools can help with the management; however, this practice can perpetuate bad habits like reuse of service accounts across applications.
  • Different business units and stakeholders, such as developers, security professionals and operational staff, have different needs and tool preferences.
User Recommendations
  • Establish a long-term machine IAM practice by creating a cross-functional fusion team.
  • Define your scope, collect machine identity use cases and establish best practices by enabling local champions to propagate their use.
  • De-emphasize legacy service account management practices with dynamic service identities (that do not require separate static accounts to be managed) for all future deployments.
  • Start building essential basic capabilities by focusing first on supporting current legacy models through broad discovery and life cycle management across multiple machine identity types. Then, build capabilities for dynamic service identity management for future deployments, such as issuance, credentialing, access control and monitoring.
  • Use a best-of-breed approach via multiple tools that can provide continuous observability (discovery, monitoring and behavior analysis) of machines.
  • Provide tailored guidance to developers, infrastructure and operations, DevOps, and security teams by defining guide rails around the secure use of machine identities and credentials.
Gartner Recommended Reading

Decentralized Identity

Analysis By: Michael Kelley, Akif Khan, Arthur Mickoleit
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Emerging
Definition:
Decentralized identity (DCI) democratizes digital identity by decentralizing both the storage and the use of identity data. The primary benefits of DCI are privacy, anonymity and user autonomy. DCI tools include an identity trust fabric, a digital wallet, which is tied to an entity (user), and verifiable credentials (VCs), which represent identity attributes used to prove identity claims.
Why This Is Important
DCI can help to solve problems related to identity verification, account takeovers, fraud, privacy and security. It is driven by VCs, which represent proofs for claims about identity attributes, like employment status, citizenship or authorizations to access applications and data. But the process of doing this with DCI, compared with the real world, represents magnitudes of improvement in terms of efficiency, cost and assurance.
Business Impact
Users gain greater control of their identities and data, and service providers (SPs) gain higher trust, speed to value and confidence, as well as lower exposure to risk from identity data leaks. Currently, SPs collect huge amounts of identity information about users for every interaction to increase assurance to an acceptable level. DCI can provide trust, security, privacy, convenience and portability of identity data for end users without needing centralized data, thereby reducing risks of data breaches, account takeovers and privacy compliance violations.
Drivers
  • Vendor investments in DCI: In addition to influential vendors (such as IBM, Microsoft and Ping Identity) making significant investments in DCI, Gartner has been tracking more than 80 startups or established vendors of DCI technologies and DCI components.
  • Government activity: Public sectors are increasingly shaping DCI trends. The EU has ratified eIDAS 2.0, which mandates the provisioning of identity wallets (used in DCI) to citizens by 2026. Other national, regional and local authorities are exploring and investing in DCI use cases across public and private sectors. Examples include Finland, the U.K.’s National Health Service, Buenos Aires in Argentina and the Basque Country region in Spain.
  • Regulations: Countries continue to formalize requirements for user privacy, establishing regulations for collecting and securing large amounts of user data. DCI complies with privacy regulations through decentralizing user data. In addition, basic use cases for know your customer (KYC) and anti-money laundering are being developed for DCI use cases.
  • Client and overall market interest in DCI: Interest is increasing due to the momentum of companies beginning to use DCI approaches to enable new digital business opportunities while maintaining client privacy.
  • Standards: Standards are maturing, led by entities such as the World Wide Web Consortium (W3C), Trust Over IP, the OpenWallet Foundation and OpenID for Verifiable Credentials (OID4VC) to create a consistent approach to DCI.
  • User experience (UX): Asking users to repeatedly go through identity verification (IDV) and affirmation processes for every new online interaction with an SP is a broken model. Significant friction can be removed from UX if users could verify once and then assert their identity to each new SP, as needed, using an identity wallet with full control over their identity data. DCI can make high-trust IDV available to a larger number of SPs without having to invest in discrete IDV tools.
Obstacles
  • Authority of issuers: Ensuring that an organization has the authority to issue a VC (such as only an accredited facility issuing educational credentials) is a challenge.
  • Infrastructure standardization: Part of the process of building out DCI is having standard and straightforward processes for adding issuers of VCs as well as validators for any DCI network; uniformity will be required to drive adoption.
  • Interoperability: Most development is taking place in pockets, and standards are maturing slowly.
  • Technical challenge: Concerns exist about performance, cryptographic key management, scalability, maturity and wallet standards.
  • Regulations: More work is required for how verifiable claims can be used in regulated use cases, such as driver’s license and other government records or KYC and AML, as required in financial services.
  • Security: Identity wallets must enforce strong authentication controls to ensure that only the person whose identity attributes are held within the wallet can make identity assertions. Wallet recovery processes must also be secure.
User Recommendations
  • Explore use cases by identifying tasks and processes that are expensive, complex and time-consuming in the real world, which will benefit from a VC approach.
  • Follow government progress around use cases for citizen IDs for bootstrap opportunities, as well as the various open-source initiatives like those from Walt.ID, SpruceID, etc.
  • Track new developments in emerging standards like Trust DID Web (did:tdw) and Key Event Receipt Infrastructure (KERI), which may help to address some of the technical challenges associated with decentralized trust infrastructure and registries.
  • Observe the development of organization credentials taking place with verifiable legal entity identifiers from the Global Legal Entity Identifier Foundation for the potential of establishing authoritative VC issuers.
  • Be prepared for early disruption in the DCI market. Gartner expects some chaos with mergers and acquisitions, and vendors exiting the business.
Sample Vendors
1Kosmos; Avast; IBM; IdRamp; Interac; Lissi; Microsoft; Ping Identity; Scytáles
Gartner Recommended Reading

Identity Wallets

Analysis By: Michael Kelley, Akif Khan, Arthur Mickoleit
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Identity wallets, in the form of both mobile and web apps, enable users to store, manage and selectively disclose digital identity data from different sources and for various purposes. Users can also use identity wallets to hold their credentials to verify claims.
Why This Is Important
An identity wallet provides an individual with greater control over their identity data and can potentially enable higher trust for verification of identity claims. For service providers, identity wallets can equip new service models for consented sharing of identity data. Use cases can involve commercial and government entities for issuers and verifiers of credentials and attributes. Governments are actively adopting standards and regulations around identity wallets.
Business Impact
Identity wallets help individuals manage personal identity data. For example, for applications like ID cards, digital passports, mobile driver’s licenses and employment status. The data managed by identity wallets include verifiable credentials for decentralized identity (DCI), which can be used for authentication and authorization, as well as potentially for other digital representations of electronic data, like access cards, airline or concert tickets.
Drivers
  • Privacy and security: Identity wallets used with DCI systems prioritize benefits like security, privacy and anonymity through privacy preserving protocols and selective disclosure.
  • Health information: Identity wallets can safely and securely share health information from patients to medical providers.
  • Citizen credentials: Identity wallets help manage mobile driver’s licenses and other documents providing proof of identity and entitlements. All EU member states are required to offer identity wallets free-of-charge for citizens by the end of 2026.
  • Growing traction of DCI: Interest in identity wallets is growing with increased interest in DCI. Global standards bodies, like the Open Wallet Foundation, the World Wide Web Consortium and Trust Over IP, are defining standards for how verifiable credentials and decentralized identifiers function in identity wallets. This is driving additional use cases. These standards enable the creation of open interoperable identity wallet services.
  • User experience (UX): Identity wallets will reduce the need for users to repeatedly verify their identity across multiple service providers. Mobile devices will become the primary means for verifying identity claims, especially as services, payments and other use cases move to mobile consumption. Asserting an identity claim from already-verified identity attributes will reduce onboarding friction and likely serve as a competitive advantage for service providers.
  • Future monetization of identity data: Identity wallets are focused on nonremunerated consent for sharing personal identity data. In cases where identity wallets are tied to a DCI use case, Gartner anticipates new markets where an individual grants consent of their personal data for commercial use in return for remuneration or other rewards.
Obstacles
  • Market understanding: There is confusion about the term “identity wallet.” It can refer to a proprietary mobile ID app, a digital wallet where identity data is confined to a centrally defined ecosystem, or to an open standards-based identity wallet that enables decentralized, portable and interoperable identity.
  • Wallet standards: The market is actively working on standards and strategies for interoperability. The OpenWallet Foundation is currently working on defining an open standard for an identity wallet; however, a universal wallet is still not available.
  • User acceptance: The adoption of identity wallet technologies will be driven by discrete use cases, instead of a universal use case that applies to all users for some time.
  • UX: The identity wallet interface must be easy to use and intuitive. A focus on device-based approaches could disenfranchise users with no access to mobile phones.
  • Trust and recoverability: Robust, standardized and secure recovery options, regardless of the wallet manufacturer, have yet to surface in the market.
User Recommendations
  • Prepare to support different digital and identity wallets for varied use cases. For example, a wallet for concert tickets, a government-issued wallet for citizen-identity information, a personal wallet holding banking, employment and educational credentials, or a wallet for storing cryptocurrency or processing payments.
  • Explore emerging use cases, like verifiable credentials for DCI, cryptocurrency and non-fungible tokens, while supporting traditional use cases. For example, digital representations of physical things, such as airline and events tickets, and government-related documents like driver’s licenses, ID cards and passports.
  • Observe or participate in shaping regulations, standards and reference frameworks that are relevant to your geography. For example, the revised EU regulation, eIDAS 2.0, was ratified in March 2024, and other governments are involved in large-scale pilots.
  • Investigate the value of identity wallets for representing identity in online digital communities, like Web 3.0 and metaverse applications.
Sample Vendors
Apple; Google; ID.me; Interac; Lissi; Microsoft; Nuggets; Ping Identity; Scytáles; Walt.id
Gartner Recommended Reading

Identity Threat Detection and Response

Analysis By: Mary Ruddy
Benefit Rating: High
Market Penetration: More than 50% of target audience
Maturity: Adolescent
Definition:
Identity threat detection and response (ITDR) is a discipline that leverages tools and best practices that secure the identity and access management (IAM) infrastructure itself from attacks. Various ITDR tools can enforce administrative user hygiene, detect threats, respond to different types of attacks or restore normal operation as needed.
Why This Is Important
Identity is foundational for security operations (identity-first security). Therefore, IAM infrastructure must be operated with a security mindset as threat actors are targeting the identity infrastructure itself. Credential abuse is a top attack vector, according to the 2025 Data Breach Investigations Report by Verizon Business. Organizations must increase the maturity of their process for protecting their IAM infrastructure. ITDR can add additional layers of security to IAM and cybersecurity deployments.
Business Impact
Securing your IAM infrastructure is mission-critical for identity and security operations. If your accounts or IAM infrastructure itself are compromised, attackers can take control of your systems and disrupt operations. Protecting your IAM infrastructure is a top priority. “Business-as-usual” processes that seemed adequate before attackers targeted identity tools directly are no longer sufficient. This can require multiple ITDR-enabling tools, which may include tools already within the organization’s portfolio.
Drivers
  • More sophisticated attackers are actively targeting the IAM infrastructure itself. For instance:
    • Administrator credential misuse is now a primary vector for attacks against the IAM infrastructure.
    • Attackers can use administrative permissions to gain access to the organization’s global administrator account or trusted SAML token-signing certificate to forge SAML tokens for lateral movement.
  • Modern attacks show that conventional identity hygiene is only part of the solution. There is no such thing as perfect prevention. Multifactor authentication and entitlement management processes can be circumvented, and the supporting/enabling tools generally lack mechanisms for detection and response if something goes wrong.
  • ITDR is needed as an additional layer beyond immutable data vaults, access management (AM), identity governance and administration, privileged access management, security information and event management, and a security operations center or outsourced managed detection service.
  • IAM and infrastructure security controls have major detection gaps. IAM is traditionally used as a preventive control, whereas infrastructure security is used broadly but has limited depth when detecting identity-specific threats. ITDR demands more specific capabilities that operate with lower latency than general-purpose configuration management, detection and response tools.
  • Ensuring the integrity of IAM infrastructure requires organizations to deploy a more granular govern, identify, protect, detect, respond and recover loop. This includes combining foundational practices with ITDR:
    • Govern, a new element of the NIST CSF 2.0 framework, to ensure that ITDR activities are effective and evolve with your organization.
    • Identify threats in your environment, to ensure your ITDR program meets current requirements.
    • Protect your IAM infrastructure with hygiene. At minimum, this includes IAM infrastructure administrative accounts. Broader end-user entitlement management is a key part of an overall IAM program.
    • Detect indications of abnormal identity activity quickly and accurately before material damage is done.
    • Respond to incidents with appropriate levels of automation, both to block the activity and to make needed changes to policies and configuration posture to avoid recurrences.
    • Recover quickly, in the rare circumstances when this is necessary.
Obstacles
  • ITDR requires coordination between IAM and security functions, which can be difficult for some identity teams without a security orientation.
  • Awareness of IAM administrator hygiene, detection and response best practices is low. Organizations tend to operate identity tools in silos, which prevents them from sharing risk signals and prioritizing overall hygiene activities.
  • Multiple capabilities are required to fully protect the IAM infrastructure. These include closely monitoring configuration changes to root IAM administrator accounts, detecting when IAM tools are compromised, enabling rapid investigations and efficient remediation, and the ability to quickly revert to a known good state. This requires multiple vendors.
  • There are many different tools with ITDR capabilities that vary widely in their strengths. Therefore, organizations will need to choose multiple tools to achieve full coverage.
User Recommendations
  • Include an ITDR strategy in your formal IAM program. Prioritize securing the IAM infrastructure with tools to discover and monitor identity attack techniques, protect identity and access controls, detect when attacks are occurring, and enable fast remediation.
  • Look for capabilities in existing and new specialized tools that will provide visibility across your IAM ecosystem, prioritize remediation efforts, and demonstrate (over time) a reduction in the attack surface. Leverage multiple tools to provide all needed IDTR capabilities.
  • Leverage current and emerging IAM standards to orchestrate your IAM infrastructure to operate more as an identity fabric that shares risk signals so that it is easier to detect identity threats. Direct the alerts generated by ITDR capabilities to your centralized security operations center.
  • Mature organizations can use the MITRE ATT&CK framework to correlate ITDR techniques with attack scenarios to ensure that at least well-known attack vectors are addressed. Above all, prevent administrator accounts from being compromised.
  • Combine foundational identity hygiene, such as reducing standing privileges, with ITDR. Manage security posture and configuration of user directories and token generators.
Sample Vendors
Cisco; CrowdStrike; Delinea (Authomize); Gurucul; Microsoft; Netwrix; Proofpoint; Semperis; SentinelOne; Silverfort
Gartner Recommended Reading

Multidevice Passkeys

Analysis By: James Hoover, Yemi Davies, Nayara Sangiorgio, Ant Allan
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Multidevice passkeys are public-key credentials used within FIDO2 user authentication protocols published by the FIDO Alliance. The credentials synchronization is possible across multiple devices (phones, tablets and PCs). Authentication from each device is typically enabled by a device-native biometric method, unlocking the credentials. Passkeys on a phone can be used on another unsynced device via a QR code-initiated Bluetooth connection.
Why This Is Important
A user authentication method should provide credence in an identity claim, sufficient to reduce account takeover risks within an organization’s risk tolerance, ideally without adding unnecessary friction to the user journey. Multidevice passkeys provide a basis for passwordless authentication with, at best, the same user experience (UX) as unlocking a device with face or fingerprint biometrics. In some use cases, multidevice passkeys may obviate the need for multifactor authentication (MFA).
Business Impact
Identity and access management (IAM) and other cybersecurity leaders across all industry verticals and geographies can benefit from adopting multidevice passkeys for customer authentication, which can:
  • Improve UX by eliminating passwords
  • Elevate trust by providing phishing-resistant authentication
  • Let customers enroll once and use the same credentials for login from any synced device
Drivers
  • The imperative to avoid the vulnerabilities, risks and user frustration associated with passwords, which drives interest in passwordless authentication generally.
  • Wide availability of FIDO2 platform authenticators in Apple, Google and Microsoft OSs and passkey support in personal password management (PPM) apps (e.g., 1Password and Dashlane). Specifically, users can sync multidevice passkeys across all their devices within the vendors ecosystem, eliminating the need to enroll each device separately for every service provider.
  • Cross-device authentication enables a user to use a passkeys-enabled phone as a FIDO2 roaming authenticator to log in to an app or website from another device that:
    • Can’t support passkeys
    • Sits in a different vendor ecosystem
    • Is not owned by customer
  • Web browsers and customer IAM tools widely support FIDO2 and web authentication, allowing the use of various FIDO2 authenticators, including multidevice passkeys. Specialist vendors further facilitate the use of passkeys for customer authentication.
  • Increasing advocacy of passkeys by Apple, Google and Microsoft. Visible support for login with passkeys from well-known social networks and from service providers, such as Best Buy, Cloudflare, eBay, GitHub, Google, Microsoft, PayPal, Stripe and WordPress.com.
Obstacles
  • Syncing is currently limited to single-vendor ecosystems (i.e., across OSs and browsers from the same vendor or across devices with the same PPM app). To log in from a device outside that vendor ecosystem, a customer would have to reenroll or use cross-device authentication (scanning a QR code to connect via Bluetooth), eroding UX.
  • Synced passkeys can be shared among contacts at the user’s discretion. They are no longer in the user’s sole possession and do not constitute a possession factor for the purposes of MFA.
  • There is no significant adoption of passkeys or awareness of passkeys as an option among customers. Service providers will be very wary of taking people’s passwords away until it’s clear that passkeys work reliably, limiting the security benefits.
  • People’s privacy concerns that ecosystem vendors might collect and monetize information about their online behaviors may be an inhibitor.
User Recommendations
  • Support and advocate passkeys as an alternative to passwords for those who can use them. Focus on the UX benefits, highlight passkeys as a login option and make enrollment easy.
  • Introduce an additional authentication factor for MFA. However, this might be waived if regulatory requirements are absent.
  • The weakness of most passwords lead to a need for a second factor and passkey is a stronger alternative. Even if a passkey doesn’t qualify as MFA, it may still be strong enough by itself for low-risk transactions.
  • Consider device-bound passkeys as an alternative to multidevice passkeys for some customer authentication needs (e.g., in mobile apps enabling high-value or sensitive transactions).
  • Prefer device-bound passkeys for workforce authentication. Take care to segregate device-bound and multidevice passkeys.
Sample Vendors
Apple; Corbado; Google; Hanko; Microsoft; Okta; Ping Identity
Gartner Recommended Reading

Journey-Time Orchestration

Analysis By: Akif Khan
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Journey-time orchestration (JTO) solutions improve risk management along digital user journeys and deliver optimized user experience (UX). Most organizations manage many identity verification, authentication and account takeover (ATO) prevention tools, and adjacent capabilities such as access management. A JTO solution manages vendor integrations, simplifies assessment of risk at each event in the journey, and facilitates tailored and risk-appropriate UX delivery.
Why This Is Important
Protecting the integrity of digital user journeys and offering a compelling UX is the foundation on which digital transformation is built. Organizations without available developers struggle to manage the broad range of capabilities that this requires, including identity verification, user authentication, ATO prevention, identity provider (IdP) resilience and A/B testing. Further complexity arises when integrating with adjacent capabilities, such as access management and risk analytics, and UI components.
Business Impact
Using a JTO solution can:
  • Reduce the operational complexity of managing multiple vendor integrations, while integrating multiple required functions into shared/common journeys, which can lead to cost savings.
  • Empower business users to do more in a low-code/no-code manner by removing the need to customize business logic in code.
  • Improve risk management efficacy along the digital user journey, and help organizations manage the delicate balance between security and UX. Increasing security while improving UX is an aspiration for most businesses.
Drivers
  • Managing multiple vendor integrations is a drain on an organization’s resources at a time of skills shortages. Moving that development effort to the JTO tool reduces cost and complexity.
  • Security teams and app developers are both seeking more tailored, risk-appropriate UX, which is easier to achieve with a JTO solution due to the fine-grained user journey control intrinsic to such solutions. The JTO solution optimally acts as the connective thread between the analytics solutions and the UI layer to reduce fraud risk while enabling a great UX.
  • The need to facilitate A/B testing in DevOps is pushing the adoption of JTO. Optimization of a risk management strategy is facilitated by a strong JTO platform in the form of A/B testing. For example, traffic could be split across two different identity verification vendors to assess which delivers better conversion rates.
  • Organizations seek to improve resilience in their vendor connections. In high-throughput B2C use cases, vendor uptime is critical. For certain categories of capability, a JTO platform can improve such resilience. For example, if a given vendor is down or showing too high a degree of latency, the JTO vendor can be configured to use a designated alternative vendor, if appropriate.
  • Enabling robust integrations with access management and other identity and access management (IAM) tools introduces additional efficiencies to cybersecurity organizations. Creating or acquiring JTO capabilities by many customer identity and access management (CIAM) vendors is lowering the barrier to adoption and bundling JTO with the access management layer.
  • In some instances, JTO can enable access to nonstandard applications, avoiding the need for expensive application upgrades.
Obstacles
  • The cost of acquiring and implementing JTO capabilities, on top of existing IAM capabilities and tools, may not pass a cost vs. benefit analysis where the value of JTO is hard to accurately determine until tested in production.
  • JTO vendors are expected to maintain updated and certified integrations with a large number of downstream IAM and ATO prevention vendors. This can be mitigated by a model in which some JTO solutions allow clients to add their own integrations.
  • Organizations rely too much on the JTO vendor’s roadmap for enabling new features from downstream vendors and on the JTO vendor to make all top-level data available. For example, decision or risk scores, along with metadata (the basis for the signal) from vendors that could be used in rules and policies.
  • The consolidation within the market of JTO capabilities within CIAM platforms is raising the barrier to usage for those organizations who are not using a vendor-provided CIAM platform. The acquisition of many JTO platforms has left a gap in the market for JTO capabilities that can be easily used by an organization without the need for locking in with a given CIAM platform.
User Recommendations
  • Abstract away from the complexity of managing multiple vendor integrations by leveraging a JTO solution to deliver a marketplace of ready-made connections to identity verification, authentication and ATO prevention solutions.
  • Deliver tailored and risk-appropriate UX by using a JTO solution to connect the analytics and UI layers to broker calls between systems along the user journey.
  • Assess JTO vendors’ resilience and business continuity plans carefully, given the risk of using a single vendor to manage connectivity to multiple downstream vendors.
Sample Vendors
Callsign; Darwinium; Descope; Dodgeball; IBM; Monokee; Okta; Ping Identity; Strivacity; Transmit Security
Gartner Recommended Reading

Climbing the Slope

Third-Party Biometrics

Analysis By: James Hoover, Ant Allan
Benefit Rating: High
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
Third-party biometrics uses a person’s unique morphological or behavioral traits to provide credence in a claim to an identity established for interactive access to an organization’s digital assets. Unlike device-native biometrics built in by the device/OS vendor, this technology is offered as proprietary software. The software may be deployed in several ways — local, central or decentralized — differentiated by where biometric reference data is held and where comparison and matching take place.
Why This Is Important
Authentication should provide credence in an identity claim, sufficient to bring account takeover risks within an organization’s risk tolerance, ideally without unnecessary user friction. Using third-party biometrics offers several advantages over device-native biometrics and other credential-based methods. It potentially frees the person from having to remember a password or carry a token, thus optimizing user experience (UX), and provides greater user accountability, as biometric traits are not easily shared.
Business Impact
Identity and access management (IAM) and other cybersecurity leaders in many industry verticals and geographies may benefit from third-party biometrics, which can:
  • Be adopted in a range of use cases for workforce and customer authentication
  • Be used alone or as a component of multifactor authentication (MFA)
  • Improve trust and accountability
  • Optimize UX, especially when enabling passwordless authentication
  • Enable high-assurance remote account recovery
Drivers
  • Increased emphasis on UX more generally, for both workforce and customer authentication, given the imperative to improve employee experience and customer experience within a total experience strategy.
  • Increasing interest in and successful deployment of passwordless authentication by using biometrics in customer-facing mobile apps and (less often) web apps, especially in banking, as well as in proprietary smartphone apps for passwordless MFA.
  • Limitations of device-native biometrics is driving interest in third-party biometrics that can make use of standard inputs, such as cameras for face or palm and microphones for voice.
  • Third-party biometrics offers organizations greater control over configuration, enrollment and choice of modes than device-native biometrics. Nonlocal (central or decentralized) architectures enable portability and consistency across devices and channels.
  • Banking apps using device-native biometrics increasingly add third-party biometrics for higher-risk transaction authorization.
  • Organizations adopting identity verification (“ID plus selfie”) for customer onboarding often want to leverage biometric face recognition data for customer authentication and account recovery across multiple channels. This potentially extends to workforce authentication.
  • Voice recognition, in combination with other signals, has been successfully used in contact centers as a more effective alternative to knowledge-based verification, which people often find frustrating and attackers readily defeat. It is also a natural fit for virtual personal assistant or “smart speaker” use cases. It’s possible to use the same biometric reference data for the contact center and for mobile apps.
Obstacles
  • Device-native biometrics are widely available and familiar, enhancing UX. Their use doesn’t demand significant investments.
  • Privacy laws are often seen as a barrier. While they do not necessarily obstruct implementation, they add administrative and technology overheads.
  • People may object to third-party biometrics due to a variety of concerns, such as the risk of data being exposed or used in wrongful ways, the fear of being spied on, demographic bias, and religious, cultural and civil rights objections.
  • Protecting third-party biometrics against presentation attacks (e.g., using a picture or video of the target’s face) presents multiple challenges:
    • Vendors’ presentation attack detection (PAD) claims require careful scrutiny; exhaustive evaluation is beyond the capability of most buyers.
    • Active PAD techniques may erode UX benefits.
    • Generative AI (deepfake) attacks, especially as part of injection attacks, demand more sophisticated countermeasures.
  • Usability and reliability vary across modes, populations and use cases, limiting the success with any single mode.
User Recommendations
  • Evaluate device-native biometrics — alone or in combination with other credentials as a way to optimize authentication UX or enhance trust, especially for everyday authentication (i.e., for lower-risk interactions), before looking at third-party biometrics.
  • Implement third-party biometrics to address specific use cases that have more stringent trust or accountability requirements or particular operational or UX needs. These use cases may include such things as account recovery and transaction authorization, not just login. Offer a choice of modes (e.g., face and voice) and combine modes for higher trust.
  • Fully address privacy and security needs by meeting regulatory due diligence requirements, including proportionality tests, choosing technology that can provide robust data security, and favoring privacy-preserving deployment options.
  • Mitigate the risks of attacks, including deepfake attacks, by choosing technology that can demonstrate genuine human presence and use compensating account takeover controls, including passive behavioral biometrics.
Sample Vendors
1Kosmos; Auraya; Daon; Facephi; FaceTec; iProov; Keyless; Pindrop; Spitch; Veridas
Gartner Recommended Reading

Age Assurance and Parental Consent Tracking

Analysis By: Sean ONeill
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Age assurance uses digital, biometric and validation techniques to verify users’ age group participation. It is used to prevent minors from accessing age-restricted content and digital social media platforms, and ensure compliance with many recent child protection regulations. “Age assurance” is the umbrella term for age estimation and age verification. Many regulations include parental consent tracking, a requirement often overlooked in identity assurance solutions.
Why This Is Important
Driven by the U.S. Children’s Online Privacy and Protection Act (COPPA), the U.K. Online Safety Act and similar laws, a new wave of age assurance regulations is emerging. Lawmakers are defining what content is in scope, determining valid age checks and enforcement, and aiming to limit minors’ access to age-restricted content to protect their data and restrict targeted ads, especially on social media and other platforms popular with children. Vendors must also deal with parental consent use cases, which are more complex than they appear.
Business Impact
Online vendors of age-restricted content need fast, reliable age verification that doesn’t disrupt the user experience. They must comply with evolving global laws while minimizing friction for eligible users to prevent abandonment. Vendors must add in the complexity of new compliance regulations and reporting. Managing parental consent is also required by many regulations, but not always supported by identity vendors.
Drivers
  • Parental concerns: The rise of social media, adult entertainment and age-restricted products, like tobacco and alcohol, has parents worried about their children’s online activities.
  • Compliance needs for businesses: Vendors offering these products and services must comply with new legislation to avoid legal repercussions.
  • Innovation in age assurance and consent: The new wave of regulations is prompting technology vendors to develop innovative solutions that help businesses integrate age assurance services and comply with parental consent requirements.
  • Data privacy considerations: Many of these laws are modeled after General Data Protection Regulation (GDPR) and other age assurance regulation principles for consent tracking. However, collecting data on a minor’s internet usage, even indirectly through metadata, raises concerns about:
    • Targeted advertising toward children
    • Safeguarding children’s personally identifiable information (PII)
    • Potential free speech limitations
  • Growing market for age assurance: Similar to the evolution of GDPR, the new wave of age assurance and consent legislation is expected to attract new vendors with innovative approaches.
  • Client needs: End-user clients (businesses) will seek assistance in understanding the relevant laws and implementing compliance measures to avoid the penalties outlined in the legislation(s).
  • Age-gated content management: Many online vendors offer a mix of products and services with varying age restrictions. For instance, a movie streaming platform may need different age assurance methods for content rated G, PG, PG-13, R and NC-17.
Obstacles
  • Lack of traditional credentials: Unlike adults, minors often have no formal IDs, making age and parental consent verification challenging for sellers.
  • User experience vs. assurance: If not balanced with usability, age checks and parental consent can add friction, risking customer loss.
  • Cost considerations: Risk-based analysis is needed, as age assurance adds costs and may impact business models.
  • Parental consent technology: Such technology is still developing, which may hinder effective compliance.
  • Law vs. market readiness: New regulations often outpace vendor capabilities due to legal uncertainty and slow adoption.
  • Free speech concerns: Lawsuits have overturned some age assurance rules, citing infringement on legal adult access and free speech rights.
User Recommendations
  • Determine whether your services are affected by age assurance or parental consent laws on a product-by-product basis.
  • Choose vendors with user-friendly age assurance methods that minimize user disruption.
  • Ensure that partners understand local child protection and age assurance regulations in their service areas.
  • Check whether your identity provider offers age assurance capabilities or has relevant integration experience.
  • Collect only the minimum data needed to verify age and avoid retaining a minor’s personal data. Regulations limit the collection and storage of such data.
  • Partner with reputable age assurance vendors and consult organizations like NIST, eIDAS or the Age Verification Providers Association for guidance.
Sample Vendors
AU10TIX; BlueCheck; FaceTec; Jumio; Persona; PRIVO; Veridas; Veriff; Yoti
Gartner Recommended Reading

SCIM

Analysis By: Brian Guthrie
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
The System for Cross-Domain Identity Management (SCIM) specifications provide a protocol, schema definition and extension model for provisioning and managing identity data in cloud/hybrid applications and services. The protocol supports create, read, update and delete (CRUD) operations of identity resources, such as users, groups and custom resource extensions.
Why This Is Important
SCIM has become a popular starting point for user provisioning to cloud-based targets, given its broad adoption by access management (AM) vendors and ease of deployment due to standardization. SCIM helps establish and standardize the communications and identity data exchange between identity access management (IAM) systems and applications. Formalizing and integrating SCIM standards enables posts-implementation efficiency and optimization.
Business Impact
  • Reduces the costs of building connectors for things that can communicate with SCIM.
  • Synchronizes and consolidates identity data.
  • Helps manage joiners’, movers’ and leavers’ identities in target applications that are deployed on-premises and in the cloud.
  • Is designed to be a standards-based provisioning protocol that increases an organization’s application portfolio agility and eases provisioning without needing custom connectors.
Drivers
  • Reduces technology friction by enabling user-event-based correlation of user attributes, entitlements and directory synchronization.
  • Offers implementation libraries (example: i2scim.io for Kubernetes) (that are mature enough) to dynamically discover and represent different schemas and identity resources out of the box.
  • Reduces IAM vendor lock-in.
  • Has emerged as a protocol for developing user management interfaces in SaaS and internal applications.
  • Is a replacement for many proprietary provisioning protocols.
  • Has emerged as the standard automating the exchange of user identity information between identity domains or IT systems.
  • Can translate identity data between proprietary approaches and with SCIM- supported IAM platforms.
Obstacles
  • Not all implementations of SCIM support custom extensions. SCIM may not support custom attribute extensions, even after extended schemas are finalized.
  • There can be a lack of SCIM support by applications (whether homegrown or vendor-provided).
  • SCIM is not broadly accepted and adoption is not favored over proprietary approaches to some application developers, who create their own APIs for user provisioning.
  • Implementation requires a high level of technical expertise. The complexity may require additional resources and expertise, affecting timelines.
  • Core SCIM schema does not support all attributes and use cases out of the box. Instead, it leverages a discoverable extension mechanism for all nonstandardized entities or attributes.
User Recommendations
  • Improve identity hygiene by prioritizing applications that support SCIM during new-application evaluation.
  • Use SCIM when developing inbound identity provisioning.
  • Use SCIM when implementing life cycle management in third-party systems through identity governance and administration (IGA), access management or other SCIM gateway tools.
  • Leverage SCIM-supported applications to simplify provisioning where native connectors are not available.
  • Use SCIM to avoid IAM vendor lock-in.
  • Use SCIM gateways to lower technical debt when there is no standardized protocol support. SCIM-to-SCIM gateways are solutions that translate incoming SCIM requests and expose CRUD functionality toward destinations, using proprietary protocols.
  • Include SCIM as a mandatory requirement for organizations looking to implement IGA or IAM processes.
  • Replace old, customized connectors and avoid creating new connectors by adopting SCIM, when possible.
Sample Vendors
Aquera; Curity; iC Consult; Radiant Logic; Traxion; UNIFY Solutions
Gartner Recommended Reading

Device-Bound Passkeys

Analysis By: James Hoover, Yemi Davies, Ant Allan
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
Device-bound passkeys and legacy Fast IDentity Online (FIDO) credentials are public-key credentials used within FIDO2 and older user authentication protocols published by the FIDO Alliance. The credentials are bound to a hardware authenticator (“security key”), or to a user’s PC, tablet or phone via a software authenticator. They are typically combined with a local authentication “gesture” such as a PIN or a biometric method.
Why This Is Important
A user authentication method should provide credence in an identity claim, sufficient to bring account takeover risks within an organization’s risk tolerance, ideally without adding unnecessary friction to the user journey. Device-bound passkeys and legacy FIDO credentials provide a basis for phishing-resistant passwordless authentication, as a robust alternative to widely used multifactor authentication (MFA) methods, along with better user experience (UX).
Business Impact
Identity and access management (IAM) and other cybersecurity leaders across all industry verticals and geographies can benefit from adopting device-bound passkeys and legacy FIDO credentials, which can:
  • Improve UX by eliminating passwords.
  • Elevate trust by providing phishing-resistant MFA in a variety of workforce and customer use cases.
  • Simplify the implementation of third-party biometrics (for improved accountability) in some use cases.
Drivers
  • The imperative to avoid the vulnerabilities, risks and user frustration associated with passwords, driving interest in passwordless authentication generally.
  • An increase in phishing, prompt bombing and other attacks against phone-as-a-token authentication methods, including mobile push, as well as legacy one-time password (OTP) tokens. This has led to the emerging imperative to use “phishing-resistant” MFA.
  • Continued use of legacy Universal Authentication Framework (UAF) or FIDO2 platform authenticators with device-bound credentials on phones as a robust way of enabling the use of device-native biometrics for customer authentication, for example, in mobile banking apps.
  • Wide availability of hardware tokens with device-bound FIDO credentials — legacy Universal Second Factor (U2F) and FIDO2 security keys — from many vendors. These tokens are roaming authenticators, usable across multiple devices; some embed fingerprint sensors, providing an alternative to PINs.
  • Widespread support for FIDO2 and Web Authentication in web browsers and access management (AM) tools, including Microsoft Entra ID, enabling the use of a variety of FIDO2 platform and roaming authenticators.
  • Microsoft Windows 10 and 11 support for Windows Hello for Business (WHfB), which embeds FIDO2 elements, and for FIDO2 security keys, enabling login to corporate Active Directory networks as well as the cloud (via Entra ID).
  • Microsoft Authenticator’s nascent support for device-bound passkeys enabling login from the phone to a SaaS application via Entra ID, and from another device using the phone as a FIDO2 roaming authenticator via cross-device authentication. Gartner projects that other AM vendors will follow suit.
  • Third-party vendors’ support for: Windows login using device-bound passkeys on a person’s phone in place of a FIDO2 security key; login to legacy Windows, macOS, and so on (i.e., where FIDO2 security keys can’t be used natively); and non-Entra ID passkeys.
Obstacles
  • Handling U2F or FIDO2 security keys may be difficult for some people. Smartphone apps with device-bound passkeys may provide an easier option.
  • WHfB cannot scale beyond 10 people per device. Although Microsoft states that WHfB can provide high assurance, and multifactor unlock can be enabled, some clients remain concerned about threats from employees with physical access to others’ PCs who might discover their PINs. Using FIDO2 security keys addresses both obstacles, but these have high costs and logistical overheads.
  • The use of a phone as a FIDO2 roaming authenticator for Windows login is currently limited. While options exist, they are either nascent, or require additional software.
  • Legacy applications (including older VPNs) that cannot be federated or otherwise integrated with a FIDO2-enabled identity provider (AM tool) are unsupported.
User Recommendations
  • Use smartphone apps or FIDO2 security keys with device-bound passkeys rather than legacy phone-as-a-token authentication methods and OTP hardware tokens, wherever feasible. Take care to segregate device-bound and multidevice passkeys.
  • For Windows PC and network login, and downstream access to SaaS applications, use WHfB, FIDO2 security keys or smartphone apps with device-bound passkeys. Note that using such smartphone apps will require third-party tools for the time being.
  • Be cautious about continued investment in legacy tokens — such as OTP hardware tokens, mobile push apps and X.509 public-key tokens — but note that these may be needed to support legacy nonweb applications. Tokens and apps supporting FIDO2 as well as OTP or X.509 can span transitional needs.
Sample Vendors
FEITIAN Technologies; HYPR; IDmelon; Microsoft; Okta; OneSpan (Nok Nok); Ping Identity; Yubico
Gartner Recommended Reading

Verifiable Credentials

Analysis By: Homan Farahmand
Benefit Rating: Transformational
Market Penetration: 5% to 20% of target audience
Maturity: Early mainstream
Definition:
A verifiable credential (VC) is a self-contained, trusted piece of information about an entity. VCs refer to the entity’s attributes that establish its existence and/or uniqueness. A VC is issued and cryptographically signed by an entity (issuer), passed to the user (holder) and presented to relying entities (verifiers). VCs are validated independently of the issuers. They can be used as proof of identity, entitlement, qualification, achievement and ownership.
Why This Is Important
VCs significantly improve data sharing, privacy, data security and data quality in decentralized identity ecosystems. This approach enables the independent issuance, custody and verification of verifiable attributes. VCs dramatically reduce the need for intermediaries to attest to the validity of a given set of data, facilitating the data exchange process.
Business Impact
VCs enable digitalization and automation of secure and compliant data exchange in multiparty business processes, at lower cost and higher velocity. These types of validation, common in most industries, usually require verification of entities’ credentials to admit users, triage their eligibility, perform tasks and generate output for handoff to other parties. VCs can cut onerous verification by more than 90% and reduce the risk of data proliferation and exposure.
Drivers
  • Decentralized identity (DCI) trend: The growing adoption of DCI is a key driver for implementing VCs to streamline business processes. DCI enables VCs by providing discoverable, pairwise, unique identifiers for each relationship between the identity and other entities, independent of any of the ecosystem participants. The initial deployments may rely on bring-your-own-identity (BYOI) or pseudo-DCI infrastructure (DCI architecture with centralized components).
  • Overall interest and adoption urgency: VCs can enable new digital business opportunities while maintaining entities’ privacy. They can improve the efficiency of business processes in data exchange use cases by streamlining eligibility, credentials, document or identity verification.
  • Government identification and trust initiatives: The use of VCs is becoming a key part of government identification and trust architecture strategies. Europe’s Electronic Identification, Authentication and Trust Services (eIDAS) regulation foresees identification and attribute-sharing across public and private sectors through citizen-held identity wallets. Many governments in different regions are similarly evaluating or piloting identity wallets and VCs.
  • Continuous investment: The ubiquity and influence of vendors investing in this space drive the market forward. Significant investments have been made by organizations in many industries, including governments. Several vendors, such as identity verification vendors, access management vendors, and blockchain technology providers, have embraced VCs.
  • Consistency through standards and open-source libraries: Standards and open source libraries are currently emerging and maturing. They are led by World Wide Web Consortium (W3C)-recommended standards for decentralized identifiers and VCs, Decentralized Identity Foundation specifications to create and drive a consistent approach to VCs and related technologies, and OpenID for verifiable credential family of specifications.
Obstacles
  • Establishing viable ecosystems: Ecosystems with authoritative issuer and verifier participation are essential to enable VC adoption. However, it takes time to educate organizations and users to form these ecosystems, build relevant use cases and increase the user base.
  • Changing business processes and refactoring applications: Organizations have to adapt their business processes to exchange data using VCs. They also have to refactor their identity and access management tools and applications to issue and consume VCs.
  • Lacking interoperability and standardization: As the standardization of VC continues, there has to be a parallel effort to enable interoperability between VCs issued and/or consumed in different ecosystems and existing identity protocols that are major industrywide undertakings.
  • Decentralized identity maturity: Although VCs can be implemented in the interim using wallet-based BYOI or pseudo-DCI infrastructure, their full benefit will be realized only when DCI goes mainstream.
User Recommendations
  • Evaluate candidate ecosystem participants and business processes. Identify issuers, users and verifiers, and understand the data flow among them. The analysis will reveal opportunities to implement VCs for automating data exchange.
  • Make a business case for implementing VCs in the ecosystem. It is important to educate participants on benefits such as reducing friction while substantially enhancing efficiency and improving privacy, compliance and security.
  • Implement proof-of-concept VCs that can scale over time. Start with a minimum viable solution, using the existing vendor’s capability. Ensure future-proofing architecture that considers market turbulence as key players change. This is critical to broaden and scale the solution over time. Examples include proof of employment, remote onboarding, passwordless authentication, entitlement verification and certification verification.
Sample Vendors
1Kosmos; Filancore; Finema; IBM; Microsoft; Ping Identity; SpruceID; Thales; Var Group Iberia; Walt.id
Gartner Recommended Reading

OpenID Connect

Analysis By: Erik Wahlstrom, Abhyuday Data, Yemi Davies
Benefit Rating: High
Market Penetration: 20% to 50% of target audience
Maturity: Early mainstream
Definition:
OpenID Connect (OIDC) is an identity federation protocol built on the OAuth 2.0 framework that enables web services to externalize authentication functions. It enables applications (e.g., web-based, mobile and JavaScript) to authenticate human end users, as well as obtain basic profile information over an API.
Why This Is Important
  • OIDC lets application owners and developers authenticate humans across websites and applications without having to create, manage and maintain accounts in each application/service.
  • With OIDC, you can provide single sign-on (SSO) and reuse enterprise or social accounts to access applications and APIs, improving usability, security and privacy.
  • OIDC provides crypto-agility, consent management, support for hybrid and multicloud environments and support for more client types than previously developed federation protocols.
Business Impact
Built on top of the OAuth 2.0 protocol, OIDC offers a flexible, secure, efficient alternative to SAML. Its main benefits are:
  • Improving user experience by providing authentication, authorization and consent management
  • Reducing the data entry burden during user registration with SSO and federation support
  • Providing better support for key discovery and rotation than SAML
  • Supporting token and API-centric architectures with mobile and single-page applications efficiently.
Drivers
  • Interest in adopting OIDC continues to grow to replace SAML for new client-facing and enterprise applications. The benefits that OIDC brings to API access controls, privacy regulation, consent management, step-up authentication, compliance and implementation of adaptive access will accelerate its time to plateau.
  • OIDC is a way to use a single set of user credentials to access multiple sites and APIs, improving usability.
  • OIDC has been proven to allow identity interactions to be conducted more seamlessly and with less friction for developers than XML-based standards, such as SAML, or purely proprietary implementations, and with greater security than preceding protocols.
  • OIDC is mature and well-supported. Organizations can find certified solutions through the OpenID Connect Foundation that certifies solutions against server conformance profiles of OIDC.
  • Finance, government and healthcare institutions can benefit from the increasing work to profile OIDC specifications to support, and be fine-tuned for use by, industry verticals.
  • Work is ongoing to extend OIDC to support more use cases. This includes fast trust establishment between OpenID providers and relying parties. It also means establishing standards to share risk signals using adjacent technologies such as the shared signals framework and Continuous Access Evaluation Profile [CAEP] and Risk Incident Sharing and Coordination (RISC).
  • Growing adoption of sign-in with decentralized identity (DCI) approaches using OIDC4VC, an extension of OIDC.
  • Extensions built for OIDC establish a federation of federation services (multilateral federation), which is commonly used in higher education and with select industries such as healthcare, in which a common set of policies is followed.
Obstacles
  • The list of SaaS applications supporting OIDC continues to grow; however, it still has smaller market penetration than SAML.
  • Developers often underestimate the intricacies of the protocol and build homegrown libraries with “cherry-pick” features from the specification, making implementations insecure.
User Recommendations
  • Give preference to OIDC over SAML. Use OIDC for modern application “greenfield” developments.
  • Leverage an access management tool that centralizes adaptive access, supports multiple protocols and can translate among protocols, especially between SAML and OIDC, and other proprietary security token formats.
  • Use OIDC for human user authentication, not for machines (workloads and devices). Instead, rely on machine-specific OAuth 2.0 framework flows to get tokens.
  • Use OIDC instead of proprietary API keys or authentication methods to avoid vendor lock-in and balance security, privacy, usability and scale when building and deploying applications and services.
  • Use proven and well-tested, open-source and/or vendor-provided libraries that are up to date and meet the latest security recommendations.
  • Don’t misuse the ID token to call APIs. Instead, use the access token and modern authorization frameworks to validate the access token in and behind enterprise API gateways.
Sample Vendors
Authlete; Curity; IBM; Microsoft; Okta; OpenText; Ping Identity; Red Hat; SecureAuth; Thales
Gartner Recommended Reading

Entering the Plateau

Passive Behavioral Biometrics

Analysis By: Akif Khan, Nayara Sangiorgio, Ant Allan
Benefit Rating: Moderate
Market Penetration: 20% to 50% of target audience
Maturity: Mature mainstream
Definition:
Passive behavioral biometrics silently evaluate a person’s behavioral biometric traits (e.g., gestures, keystrokes), as well as other recognition and risk signals derived from how they interact with endpoint devices and application interfaces. The technology can be used alone or, more often, as part of a broader set of analytics to mitigate new account fraud and to augment user authentication and mitigate account takeover risks.
Why This Is Important
User authentication and other methods that provide credence in an identity claim can mitigate account takeover (ATO) and fraud risks to bring them within an organization’s risk tolerance. Evaluating recognition and risk signals from a person’s normal interactions with an endpoint device and application interfaces during login and interactive sessions can elevate trust without adding unnecessary friction to the user journey, thus optimizing user experience (UX).
Business Impact
Identity and access management (IAM) and other cybersecurity leaders in many industry verticals and geographies can benefit from passive behavioral biometrics, which can:
  • Mitigate onboarding and ATO risks for workforce and customers.
  • Combine with other recognition and risk signals throughout the user journey to enable in-session continuous passive authentication within adaptive access approaches.
  • Elevate trust and accountability because biometric traits are not easily shared or mimicked.
  • Optimize UX by reducing the need to actively challenge users.
Drivers
  • Mitigation of application fraud in which an attacker attempts to open a new account using someone else’s or a synthetic identity. Passive behavioral biometrics can reliably distinguish behavior patterns associated with genuine and fraudulent activity and also distinguish between people and bots.
  • Greater interest in analytics’ consuming passive behavioral biometrics from a variety of recognition and risk signals, due to a desire to:
    • Mitigate ATO risks, where curated credentials have been compromised, without adding friction to user journeys.
    • Identify situations where a legitimate user is being coached by or is under duress from an attacker.
    • Contribute to adaptive access as part of identity-first security and a zero-trust strategy.
    • Enhance identity threat detection and response (ITDR) approaches.
    • Mitigate deepfake and other attacks against third-party biometrics.
  • Optimized employee and customer UX from adding passive behavioral biometrics to other signals analytics, which elevates the level of achievable trust, thus reducing the frequency of prompts for step-up authentication. In particular, using passive behavioral biometrics in ATO prevention counterbalances potentially spurious risk signals that can yield false positives that interrupt or abruptly curtail customer journeys.
  • Commoditization of this technology and its growing prevalence in many tools, such as bot management, mobile apps (to detect simulator and emulator use), unified endpoint management (to detect trojans and injection attacks) and within customer IAM platforms.
  • More social engineering scams in which bank customers are tricked or coerced into logging into their own accounts and transferring funds to fraudsters. Spotting signs that a user is behaving differently after login (e.g., pausing as if receiving instructions) helps detect a scam in progress.
Obstacles
  • Passive behavioral biometrics alone are unlikely to provide sufficient credence in an identity claim or reliably identify fraudulent activity or other attacks.
  • Each device requires multiple interactions to establish a baseline, making this technology unsuitable for people and use cases where login frequency is low or where use of multiple devices is high. Some modes (e.g., handling, gait) work with handheld devices only.
  • Performance can vary because of limitations in machine learning algorithms and training data, or circumstances, such as injury, prosthetics or garb.
  • Privacy laws may be a barrier to the use of biometrics for identification and authentication, and restrictions on the use of AI or other advanced analytics may also inhibit adoption.
  • People may object to biometrics out of a variety of concerns, such as the risk of data being exposed or used in nefarious ways, the fear of being spied on or subjected to demographic bias, and objections on religious, cultural and civil rights grounds.
User Recommendations
  • Leverage passive behavioral biometrics, in addition to investing in identity verification, to reduce fraud during new account opening for customers and remote onboarding of new employees.
  • Optimize authentication UX and elevate trust and accountability by implementing passive behavioral biometrics in combination with other recognition and risk signals (e.g., device and location intelligence), thus enhancing ATO prevention, adaptive access and ITDR. Recognize that passive behavioral biometrics provide less value for infrequent users, and also evaluate compensating controls.
  • Drive the broadest acceptance of passive behavioral biometrics and other analytics by being open and transparent about what data is held and how it is used, engaging in early outreach to address people’s concerns.
  • Fully address privacy and security needs by meeting regulatory due diligence requirements, choosing technology that can provide robust data security and favoring privacy-preserving deployment options.
Sample Vendors
BioCatch; Callsign; Darwinium; IBM; LexisNexis Risk Solutions; Ping Identity; Plurilock Security; TypingDNA
Gartner Recommended Reading

Appendixes


See the previous Hype Cycle: Hype Cycle for Digital Identity, 2024

Hype Cycle Phases, Benefit Ratings and Maturity Levels

Hype Cycle Phases

Phase
Definition
Innovation Trigger
A breakthrough, public demonstration, product launch or other event generates significant media and industry interest.
Peak of Inflated Expectations
During this phase of overenthusiasm and unrealistic projections, a flurry of well-publicized activity by technology leaders results in some successes, but more failures, as the innovation is pushed to its limits. The only enterprises making money are conference organizers and content publishers.
Trough of Disillusionment
Because the innovation does not live up to its overinflated expectations, it rapidly becomes unfashionable. Media interest wanes, except for a few cautionary tales.
Slope of Enlightenment
Focused experimentation and solid hard work by an increasingly diverse range of organizations lead to a true understanding of the innovation’s applicability, risks and benefits. Commercial off-the-shelf methodologies and tools ease the development process.
Plateau of Productivity
The real-world benefits of the innovation are demonstrated and accepted. Tools and methodologies are increasingly stable as they enter their second and third generations. Growing numbers of organizations feel comfortable with the reduced level of risk; the rapid growth phase of adoption begins. Approximately 20% of the technology’s target audience has adopted or is adopting the technology as it enters this phase.
Years to Mainstream Adoption
The time required for the innovation to reach the Plateau of Productivity.
Source: Gartner (July 2025)

Benefit Ratings

Benefit Rating
Definition
Transformational
Enables new ways of doing business across industries that will result in major shifts in industry dynamics
High
Enables new ways of performing horizontal or vertical processes that will result in significantly increased revenue or cost savings for an enterprise
Moderate
Provides incremental improvements to established processes that will result in increased revenue or cost savings for an enterprise
Low
Slightly improves processes (for example, improved user experience) that will be difficult to translate into increased revenue or cost savings
Source: Gartner (July 2025)

Maturity Levels

Maturity Levels
Status
Products/Vendors
Embryonic
In labs
None
Emerging
Commercialization by vendors
Pilots and deployments by industry leaders
First generation
High price
Much customization
Adolescent
Maturing technology capabilities and process understanding
Uptake beyond early adopters
Second generation
Less customization
Early mainstream
Proven technology
Vendors, technology and adoption rapidly evolving
Third generation
More out-of-box methodologies
Mature mainstream
Robust technology
Not much evolution in vendors or technology
Several dominant vendors
Legacy
Not appropriate for new developments
Cost of migration constrains replacement
Maintenance revenue focus
Obsolete
Rarely used
Used/resale market only
Source: Gartner (July 2025)

Acronym Key and Glossary Terms


OID4VC
OpenID for verifiable credentials
RISC
Risk Incident Sharing and Coordination