Microsoft has expanded its AI bug bounty program, offering up to $30,000 for detecting critical vulnerabilities in Dynamics 365 and Power Platform. Researchers will be rewarded for issues such as inference manipulation—where model behavior is twisted—and inferential information disclosure, meaning secrets exposed through AI model patterns. These highest-tier bugs, when paired with high-quality reports, qualify for the full payout. Lower-tier reports of the same severity still earn substantial amounts. Important-severity findings can fetch $6,000 to $20,000 depending on the bug’s impact and the quality of evidence, while moderate or low-severity AI issues don’t qualify under this critical or important category.
What’s in Scope—and What’s Not
The program encompasses a swath of Microsoft offerings touching business data and automated workflows. Eligible products include cloud and on-premises components of Dynamics 365 (for Sales, Finance, Commerce, HR, Supply Chain Management, etc.), plus Power Apps, Power Automate, Copilot Studio, Power Pages, AI Builder, Dataverse, and more. Not all AI weirdness is payable: prompt-injection that only impacts the attacker, hallucinated code execution scenarios, attempts to read hidden system prompts, and content-safety issues are excluded. Public bugs, dependency confusion, configuration-only weaknesses, blind XSS, and DOS attacks are generally ruled out.
Payouts & Submission Guidelines
Critical AI flaws—such as inference manipulation or disclosure—earn up to $30,000 for strong reports. Important vulnerabilities sit next in line, scaling between $6,000 and $20,000. Other categories like remote code execution (RCE), cross-tenant disclosure, and privilege escalation have their own payout maximums. Microsoft also offers a special bonus: any Dataverse privilege escalation or Plugin Sandbox “guest-to-host” escape qualifying under high-impact criteria gets an extra 20% multiplier.
To qualify, reports must use a current, fully patched version of the affected product, clearly explain attacker impact, include proof-of-concept material and environment details, and show that the issue is reproducible. Submissions go through Microsoft’s MSRC Researcher Portal and need environment IDs, repro steps, and the testing username. If a bug is eligible for multiple awards, only the highest is granted, though Microsoft has discretion to pay more.
Safety rules are tight: only assess systems and tenants the researcher owns or has permission to work on. If unauthorized data access appears, testing must stop immediately. Avoid lateral movement, phishing, or any traffic that could disrupt operations. Microsoft recommends labeling research accounts with “MSOBB” and following coordinated disclosure rules to prevent customer risk.
Also, non-AI vulnerabilities are still rewarded: critical remote code execution flaws can get up to $20,000; elevation of privilege or information disclosure up to $12,000; spoofing or tampering issues also carry payouts. Cross-tenant information leaks are especially high value, while Dataverse sandbox escapes receive bonus multipliers.
At its core, this bump in rewards reflects Microsoft’s view that AI vulnerabilities—especially ones that can be manipulated or leak sensitive data through model inference—warrant the highest priority. As AI becomes baked into business software, opportunities for attackers to abuse model behavior introduce risks that traditional bugs don’t capture.
Why this matters: Organizations relying on Dynamics 365 or Power Platform manage critical business logic and sensitive customer data. Any exploit in these platforms—especially one that can influence model outputs or extract data—could have serious implications. This updated bounty program pushes researchers to go beyond surface-level issues and dig into model security. It also sets a higher bar for what counts as a “critical” AI flaw, which may force companies to rethink how they classify threats in the AI era.