Core component of SQL Server for storing, processing, and securing data
In our experiments on SQL Server 2025, adding the startup parameter -T4671 appears to disable the new iterative password hashing mechanism (PBKDF2-based verification).
Without the trace flag, login times are significantly longer; after enabling -T4671, login performance returns to levels comparable with earlier versions.
This behavior differs from SQL Server 2022, where trace flag 4671 enabled the iterative hashing feature. It therefore appears that the semantics of TF 4671 have changed in SQL Server 2025.
One additional observation: SQL logins whose passwords were created while the new hashing mode was active continue to authenticate successfully after switching modes. Authentication does not fail, but it appears to use a slower verification path.
Resetting the password causes the login to be re-hashed under the currently active mode, which restores expected authentication performance.
Has anyone seen official documentation confirming this behavior?