Microsoft is expanding its security bug bounty focus to cover serious vulnerabilities affecting AI features in Dynamics 365 and Power Platform.
The company is offering security researchers up to $30,000 for high-quality reports involving critical AI security issues, particularly vulnerabilities that can manipulate how AI models respond or reveal sensitive information through model behavior.
The program covers Microsoft-hosted services as well as qualifying third-party and open-source components integrated into those services.
The highest rewards are available for two major AI-related impact areas:
- Inference Manipulation — changing or influencing AI model behavior in a way that creates a security impact.
- Inferential Information Disclosure — extracting information that should not be accessible through the model.
A critical vulnerability report can receive:
- $30,000 for a high-quality report
- $20,000 for a medium-quality report
- $12,000 for a low-quality report
Important-severity AI vulnerabilities can also qualify for rewards ranging from $6,000 to $20,000, depending on severity and report quality.
Broad Coverage Across Dynamics 365 and Power Platform
Microsoft’s bounty scope covers a wide range of enterprise products because these services can handle business data, customer information, applications, and automated workflows.
Eligible products include:
- Dynamics 365 Sales, Customer Service, Finance and Commerce
- Dynamics 365 Human Resources, Business Central and Supply Chain Management
- Customer Insights and Contact Center
- Power Apps and Power Automate
- Copilot Studio and Power Pages
- Power Admin and AI Builder
- Dataverse
- Selected on-premises Dynamics products
The broader Microsoft bounty program also provides rewards for other serious security issues. Critical remote code execution vulnerabilities can receive up to $20,000, while qualifying cross-tenant information disclosure issues can receive up to $20,000.
Dataverse privilege escalation and certain Plugin Sandbox guest-to-host escapes can receive an additional 20% multiplier.
What Researchers Need to Know
AI-related submissions must meet Microsoft’s severity requirements and be reproducible on the latest fully patched version of an eligible product.
A strong report should include:
- Clear reproduction steps
- A working proof of concept where appropriate
- Affected product and version details
- Environment ID and testing account information
- A clear explanation of the security impact
- Details showing whether the issue matches a high-impact scenario
Microsoft also makes a distinction between genuine security vulnerabilities and normal AI behavior. Issues such as attacker-only prompt injection, hallucinated code execution, attempts to reveal system prompts, and general content-safety problems are generally excluded.
Researchers are expected to test only environments they own or are authorized to assess. They should stop testing if unauthorized customer data becomes accessible and avoid activities such as phishing, lateral movement, disruptive traffic, or unnecessary post-exploitation.
The expanded bounty program highlights a growing shift in security research: AI features are becoming part of enterprise attack surfaces. As organizations increasingly rely on AI to access data and automate business processes, vulnerabilities in AI integrations can have consequences far beyond the model itself.