Core component of SQL Server for storing, processing, and securing data
This happens because a combination of several factors. One is a security enhancement in SQL 2025, so that password-based authentication uses PBKDF2, which means that the password is hashed 100000 times. The other factors is due to bad practice on your side:
- Using SQL authentication.
- Turning off connection pooling.
This feature was originally introduced in SQL 2022 CU12, but in SQL 2022, you had to enable it with a trace flag. The very same trace flag you tried to use to disable the feature. Well, in early builds of SQL 2025, the trace flag did indeed disable PBKDF2, but that was of course a very bad idea, since sites who had enabled the feature in SQL 2022, would suddenly have it disabled in SQL 2025.
My recommendation is that you enable connection pooling. I would also recommend that you ask yourself why you are using SQL authentication.
If you think that this is not an option for you, your best bet is to open a support case and argue that the business impact is of the magnitude that you need a trace flag.