Gartner's Market Guide for User Authentication, in its 2025 edition, contains two predictions that describe the market's absorption: by 2027, 90 percent of enterprises will fully meet their MFA needs for remote and cloud access using the native capabilities of access management tools, lowering total cost of ownership by 40 percent, and by 2027, more than 90 percent of MFA transactions using a token will be based on FIDO authentication protocols, the passkeys, natively supported in the same tools. The standalone MFA tool is becoming a feature of the access platform.

The absorption prediction

The authentication market's history is the password's slow retirement: the MFA layers added over the password, the authenticators, the tokens, each sold as a separate purchase.

The 2025 predictions describe the market's consolidation: the access management platform absorbing the MFA capability natively, the buyer's authentication needs met inside the platform they already run, and the cost of the standalone tooling removed from the stack. The absorption's mechanism is the platform's economics: the native capability bundled, the TCO reduction the prediction prices at 40 percent.

The standalone MFA tool is becoming a feature of the access platform, and the predictions are the absorption's schedule.

The 2025 Market Guide for User Authentication, and its predictions

The current edition, dated 2025, continues a series whose 2023 edition was authored by Ant Allan, James Hoover, and Robertson Pimentel.

The guide's definition is the market's purpose, stated tightly: user authentication provides credence in an identity claim for a person already known to the organization, sufficient to bring account takeover risk within the organization's risk tolerance, the cornerstone of identity-first security.

The predictions are the market's direction: the 90 percent native-MFA adoption and the 40 percent TCO reduction by 2027, and the passkey dominance, more than 90 percent of token-based MFA transactions running on FIDO protocols natively supported in the access management tools. Ninety percent is an absorption curve with a deadline, and the deadline is the buyer's planning horizon.

The +1FA critique

The guide's sharpest historical finding deserves the emphasis, because it explains the market's entire direction: most legacy MFA tools are really only +1FA tools, adding a single extra factor to a legacy password.

The critique is the market's honest core: the MFA layer that sits on top of the password inherits the password's weaknesses, and the phishing-resistant authentication the market promises requires the password's replacement, not its reinforcement. The passkey prediction is the critique's answer: the FIDO protocols that eliminate the shared secret entirely, the credential that cannot be phished because there is nothing to steal.

Most legacy MFA is really +1FA, and the guide said it first, which is why the market's future is the passkey.

The human design layer

The guide's less-quoted content is its human layer: the authentication experience's design constraints, the diversity, equity, and inclusion considerations, the socioeconomic bias in who possesses which authenticator, and the smartphone dependence that risks alienating the people without one.

The layer is the market's neglected dimension: the authentication method is a human decision, not just a technical one, and the guide's CARE standard, Consistent, Adequate, Reasonable, and Effective, is the market's design checklist. The buyer that optimizes the authentication purely on security grounds builds the friction that drives the users to the workarounds.

The authenticator is a human design problem, and the guide's CARE standard is the market's reminder that the users are the authentication's real environment.

What the guide cannot authenticate

A Market Guide names representative vendors and does not rank them, and its honest limit is the prediction's own condition: the absorption assumes the buyer's access management platform is competent enough to absorb, and the organizations running the weaker platforms will still buy the standalone tools the predictions say are disappearing.

The other limit is the password's own stubbornness: the guide's history, the 2020 edition through today, has predicted the passwordless era repeatedly, and the era keeps arriving slower than the predictions. The password's retirement keeps being scheduled, and the schedule keeps slipping, which is why the passkey prediction carries a deadline rather than a claim of completion.

Four questions for the identity buyer

Is the access platform's native MFA sufficient, or is the standalone tool still needed? The absorption prediction is the buyer's own decision. Assess the platform's native capability against the organization's actual risk, because the 40 percent TCO saving is the platform's case, not the guarantee.

Is the passkey path real or narrated? The FIDO prediction is the market's direction. Ask for the passkey deployment demonstrated across the buyer's own applications, with the fallback story for the users without the compatible devices.

Which users does the authenticator serve? The human design layer is the buyer's own population. Ask about the coverage across the user demographics, because the method that works for the office excludes someone in the field.

What is the account takeover risk tolerance, in writing? The definition's standard is the buyer's own. Set the tolerance explicitly, because the authentication investment is sized against it.

Analyst Source

Gartner Market Guide

Category definition, representative vendor list, and market guidance in this article draw on Gartner's Market Guide for User Authentication, current edition dated 2025, continuing a series whose 2023 edition was authored by Ant Allan, James Hoover, and Robertson Pimentel. The guide defines authentication as providing credence in an identity claim sufficient to bring account takeover risk within tolerance, predicts 90 percent of enterprises will meet MFA needs through native access management capabilities with a 40 percent TCO reduction by 2027, and projects more than 90 percent of token-based MFA transactions will run on FIDO passkey protocols by 2027. The guide's historical critique that most legacy MFA is really +1FA and its CARE standard are part of the series. Market Guides do not rank vendors or name Leaders.

Source research

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

A closely related read is Customer Identity & Access Management (CIAM). Gartner folded CIAM into its general Access Management quadrant years ago, and the newest edition's biggest theme, machine identities and AI agents logging in like customers, is why the merger keeps making more sense.

The neighboring coverage here is Identity Verification Solutions. Deepfake detection went from absent to decisive in three years. Each generation of identity verification gets defeated by the previous generation's data breaches or the current generation's synthetic media, and the problem never gets solved, only moved.