Skip to content
Cryptography Reviewed 2026-09-13

ASP.NET Web Forms ViewState MAC protection

What does this mean?

ASP.NET Framework Web Forms can send serialized page state to the browser and receive it on a later request. A message authentication code (MAC) lets the server check that protected state was not modified without the required key. A MAC provides integrity and authenticity; it does not by itself make the state confidential. Do not place passwords or other unnecessary sensitive data in ViewState.

Check the runtime before judging the setting

Historically, enableViewStateMac="false" could disable this protection. Patched ASP.NET runtimes enforce MAC protection despite legacy configuration attempts to disable it. Microsoft's ViewState security update explanation describes this change. A false attribute in a file therefore needs runtime and deployment verification; it is not automatic evidence of an accepted unprotected ViewState.

Sample configuration

The fragments below are alternatives inside the existing Web.config configuration. Keep the runtime patched and remove obsolete attempts to disable its protections.

Unsafe legacy intent: request that the MAC be disabled.

<system.web>
  <pages enableViewStateMac="false" />
</system.web>

Safer configuration intent: explicitly retain MAC validation.

<system.web>
  <pages enableViewStateMac="true" />
</system.web>

On a runtime that already enforces protection, changing this attribute may document the intended policy without changing behavior. It is not a substitute for security updates. Microsoft advises against disabling this protection even for pages that do not use ViewState in its EnableViewStateMac reference.

Check the protection

Use a disposable page with harmless state. Confirm a normal postback succeeds, then tamper with its state while keeping the transport encoding valid. Verify integrity-check rejection before the application performs a state-changing operation; an unrelated malformed-request failure is not the same evidence. Inspect controlled error handling without exposing keys or state contents. No executable serialized payload is required.

If legitimate postbacks fail across a web farm, check coordinated key configuration and deployment compatibility. Do not disable integrity checks to hide key mismatches. Protect and rotate exposed keys carefully; a strong MAC cannot compensate for a disclosed signing key.

ASP.NET Core distinction

ASP.NET Core does not use Web Forms ViewState or this setting. Use its Data Protection, authentication and antiforgery facilities as appropriate to the feature being built.

Continue with machineKey protection, event validation and CSRF. Integrity checks remain separate from current authorization and confidentiality requirements.