Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information through model behavior.
The program covers qualifying bugs in Microsoft-hosted services and third-party or open-source components embedded in them, provided researchers demonstrate a security impact on an in-scope service.
Under the bounty table, a high-quality report documenting critical “Inference Manipulation” or “Inferential Information Disclosure” can earn the maximum $30,000.
Medium- and low-quality reports for critical impacts are listed at $20,000 and $12,000, while important-severity findings can receive between $6,000 and $20,000 depending on report quality. Moderate- and low-severity AI submissions do not qualify for payment under this category.
The scope is broad because these platforms sit close to sensitive business data and automated workflows.
Eligible targets include Dynamics 365 Sales, Customer Service, Finance, Commerce, Human Resources, Business Central, Contact Center, Customer Insights and Supply Chain Management, alongside on-premises Dynamics products. It also covers Power Apps, Power Automate, Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse.
| Vulnerability Category / Focus Area | Impact Severity & Quality Tier | Maximum Payout / Multiplier | Scope & Qualification Details |
| Inference Manipulation & Disclosure | Critical (High / Med / Low Quality) | $30,000 / $20,000 / $12,000 | Manipulates model responses or extracts data via model behavior |
| Important AI Vulnerabilities | Important (High / Med / Low Quality) | $20,000 / $12,000 / $6,000 | High-impact functional or security flaws across AI integrations |
| Remote Code Execution (RCE) | Critical Severity | Up to $20,000 | Code execution flaws across in-scope cloud and service components |
| Cross-Tenant Information Disclosure | High-Impact Scenario | Up to $20,000 | Breaches tenant boundaries to access external organization data |
| Elevation of Privilege / Info Disclosure | Critical Severity | Up to $12,000 | Local and cloud-level unauthorized privilege escalation |
| Dataverse & Sandbox Escapes | Special High-Impact Vectors | +20% Multiplier | Dataverse privilege escalation & Plugin Sandbox host escapes |
Microsoft requires AI findings to meet its Critical or Important severity definitions and reproduce on the latest, fully patched version of an eligible product.
Researchers must submit reports through the MSRC Researcher Portal and provide the Power Platform or Dynamics environment ID, the username used during testing, and whether the bug matches a high-impact scenario.
Clear reproduction steps, proof-of-concept material, affected versions, and an explanation of attacker impact can accelerate validation and support a higher award.
Beyond AI payouts, the bug bounty program assigns up to $20,000 for critical remote code execution, $12,000 for critical elevation-of-privilege or information-disclosure flaws, and $8,000 for critical spoofing or tampering reports.
Cross-tenant information disclosure carries a $20,000 high-impact award, while qualifying Dataverse privilege escalation and Plugin Sandbox “guest-to-host” escapes can receive a 20% multiplier. A report eligible for multiple awards receives only the highest qualifying payment, although Microsoft may grant more at its discretion.
The program distinguishes exploitable AI security failures from model quirks. Prompt injection affecting only the attacker, hallucinated code execution, attempts merely to reveal a system or meta prompt, and content-safety issues are excluded.
Publicly known bugs, denial-of-service attacks, blind cross-site scripting, dependency confusion, and configuration-dependent weaknesses are also generally out of scope.
Researchers should test only in accounts and tenants they own or are authorized to assess, stop immediately if unauthorized data becomes accessible, and avoid post-exploitation, lateral movement, phishing, or disruptive traffic.
Microsoft recommends marking research tenants with “MSOBB” where possible and following coordinated vulnerability disclosure, ensuring findings reach engineers without exposing customers or production services to risk.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform appeared first on Cyber Security News.
