Microsoft Bug Bounty Offers $30K for Critical Dynamics 365, Power Platform AI Flaws
Key Takeaways Microsoft has expanded its bug bounty program to specifically target critical AI vulnerabilities within its Dynamics 365 and Power Platform ecosystems. Researchers can earn up to...
Key Takeaways
- Microsoft has expanded its bug bounty program to specifically target critical AI vulnerabilities within its Dynamics 365 and Power Platform ecosystems.
- Researchers can earn up to $30,000 for uncovering flaws related to AI inference manipulation or inferential information disclosure.
- The program covers a wide array of Microsoft-hosted services and embedded third-party components, emphasizing high-impact security implications.
- Beyond AI, significant bounties are also offered for critical Remote Code Execution (RCE) and cross-tenant information disclosure.
Microsoft Boosts Bug Bounty for Critical AI Flaws in Dynamics 365, Power Platform
Microsoft has significantly augmented its bug bounty program, now offering up to $30,000 to cybersecurity researchers who identify critical artificial intelligence vulnerabilities within its Dynamics 365 and Power Platform suites. This strategic move underscores Microsoft’s sharpened focus on mitigating risks associated with AI models, particularly those that could lead to inference manipulation or unauthorized information exposure through model behavior.
Table Of Content
The updated program encompasses eligible bugs found in Microsoft-hosted services, as well as any third-party or open-source components integrated within these platforms. To qualify for a reward, researchers must conclusively demonstrate a tangible security impact on an in-scope service.
Payout Structure for AI Vulnerabilities
Under the revised bounty framework, the highest reward of $30,000 is reserved for top-tier reports detailing critical “Inference Manipulation” or “Inferential Information Disclosure” vulnerabilities. Should the quality of the report for a critical impact be rated as medium or low, payouts are adjusted to $20,000 and $12,000, respectively. For important-severity findings, researchers can expect between $6,000 and $20,000, depending on the report’s quality. It is important to note that AI submissions categorized as moderate or low severity do not qualify for monetary rewards under this specific bounty category.
| Vulnerability Category / Focus Area | Impact Severity & Quality Tier | Maximum Payout / Multiplier | Scope & Qualification Details |
| Inference Manipulation & Disclosure | Critical (High / Med / Low Quality) | $30,000 / $20,000 / $12,000 | Manipulates model responses or extracts data via model behavior |
| Important AI Vulnerabilities | Important (High / Med / Low Quality) | $20,000 / $12,000 / $6,000 | High-impact functional or security flaws across AI integrations |
| Remote Code Execution (RCE) | Critical Severity | Up to $20,000 | Code execution flaws across in-scope cloud and service components |
| Cross-Tenant Information Disclosure | High-Impact Scenario | Up to $20,000 | Breaches tenant boundaries to access external organization data |
| Elevation of Privilege / Info Disclosure | Critical Severity | Up to $12,000 | Local and cloud-level unauthorized privilege escalation |
| Dataverse & Sandbox Escapes | Special High-Impact Vectors | +20% Multiplier | Dataverse privilege escalation & Plugin Sandbox host escapes |
Broad Scope Reflects Platform Importance
The extensive scope of the program highlights the critical role these platforms play in handling sensitive business data and automating complex workflows. Eligible targets span a comprehensive list of Dynamics 365 products, including Sales, Customer Service, Finance, Commerce, Human Resources, Business Central, Contact Center, Customer Insights, and Supply Chain Management, alongside their on-premises counterparts. The Power Platform components covered include Power Apps, Power Automate, Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse.
For AI findings to be considered, they must meet Microsoft’s definitions for Critical or Important severity and be reproducible on the latest, fully patched versions of the specified products.
Reporting Requirements and Exclusions
Researchers are required to submit their findings via the MSRC Researcher Portal. Submissions must include the Power Platform or Dynamics environment ID, the username utilized during testing, and an indication of whether the bug aligns with a high-impact scenario. Providing clear reproduction steps, proof-of-concept materials, details of affected versions, and an explanation of the potential attacker impact can significantly expedite the validation process and support a higher reward.
Beyond AI-specific payouts, the broader bug bounty program offers up to $20,000 for critical remote code execution flaws, $12,000 for critical elevation-of-privilege or information-disclosure vulnerabilities, and $8,000 for critical spoofing or tampering reports. Cross-tenant information disclosure scenarios can yield a $20,000 high-impact award. Furthermore, qualifying Dataverse privilege escalation and Plugin Sandbox “guest-to-host” escapes are eligible for a 20% multiplier on top of their base reward. While a report may qualify for multiple awards, only the highest applicable payment will be granted, though Microsoft reserves the right to offer additional compensation at its discretion.
Microsoft explicitly distinguishes exploitable AI security failures from mere model quirks. Out-of-scope issues include prompt injection affecting only the attacker, hallucinated code execution, attempts solely to reveal system or meta prompts, and content-safety concerns. Similarly, publicly known bugs, denial-of-service attacks, blind cross-site scripting, dependency confusion, and configuration-dependent weaknesses are generally excluded from the program.
What You Should Do
- Researchers must conduct testing exclusively within accounts and tenants they own or are explicitly authorized to assess.
- Immediately cease testing if unauthorized data becomes accessible.
- Refrain from engaging in post-exploitation activities, lateral movement, phishing, or any disruptive network traffic.
- Microsoft recommends marking research tenants with “MSOBB” where feasible.
- Adhere to coordinated vulnerability disclosure practices to ensure findings reach engineers responsibly without jeopardizing customers or production services.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.