Back Msdynamicsworld Squashing vulnerabilities: Microsoft udpates Dynamics 365 bug bounty program
Microsoft revealed updates to its bug bounty program for Dynamics 365 and Power Platform with a new structure and new awards. Researchers are eligible for bounty awards between $1,250 and $60,000.
The bug bounty updates hint at a renewed interest in cybersecurity vulnerabilities as attack surfaces grow in size and generative AI-coding tools accelerate zero day vulnerabilities. A category of “High-Impact Scenario Awards” provide award multipliers of as much as 100 percent. Among the high impact scenarios are critical severity cross-tenant vulnerabilities, Power Platform escalation of privileges in Dataverse from an entry point, and Dataverse Plugin Sandbox “guest to host” escape.
See also: Misconfigured Microsoft Power Pages targeted in new data theft campaign
There is a dedicated category of AI bounty awards. Inference manipulation and inferential information disclosure offer award amounts between $12,000 and $30,000. Most other vulnerabilities are grouped under general awards: deserialization of untrusted data, code injection, authentication issues, server-side request forgery, and improper access control to name just a few.
The bug bounty applies not only to Microsoft’s own products but to third-party and open source components included with them.
This approach marks the latest step in Microsoft’s bug bounty program, which launched in 2019. The company added high impact scenarios for business apps in 2022, followed by Zero Day Quest Award Multipliers in 2024, and a category of AI Bounty Awards in 2025.
Microsoft offered a scope list of products that are eligible under the bounty program. The laundry list of apps includes many D365 online offerings such as D365 Sales, Customer Service, Field Service, Business Central, Supply Chain Management, and less well known offerings like Remote Assist and Center. The list extends to D365 on-prem products like D365 Finance and Operations, CRM, GP, NAV, and SL, together with Power Apps, Power Automate, Copilot Studio, Power Pages, and AI Studio. The bug bounty applies comprehensively to most Microsoft business apps.
To qualify for the bug bounty, researchers need to meet certain basic eligibility requirements. First, a vulnerability needs to be what Microsoft defines as “Critical or Important severity,” and must be reproducible on one of the products or services within the Scope Services and Products. Researchers interested in bounties need to submit their finds through the MSRC Research Portal, tell Microsoft how the vulnerability submission qualifies, offer a D365 or Power Platform ID, and the username of the account used to spot the vulnerability.
For researchers interested in bug hunting, options include signing up for a free trial of D365. Microsoft encouraged researchers to check out documentation and training for its systems, as well as guidance on extending Copilot capabilities to finance and operations apps.
FREE Membership Required to View Full Content:
As the assistant editor at MSDynamicsWorld.com, Eamon helps to oversee editorial content on the site and supports site management and strategy. He can be reached at [email protected] .
Before joining MSDynamicsWorld.com, Eamon was editor for SearchNetworking.com at TechTarget, where he covered networking technology, IoT, and cybersecurity. He is also the author of multiple books and previously contributed to publications such as the Boston Globe, Milford Daily News, and DefenceWeb.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
