Digital Marketing Agency | SEO, Paid Social & PPC

Share This Post

Microsoft Bounty Programs: Microsoft strongly believes close partnerships with researchers make customers more secure. Security researchers play an integral role in the ecosystem by discovering vulnerabilities missed in the software development process. Each year we partner together to better protect billions of customers worldwide.

If you are a security researcher that has found a vulnerability in a Microsoft product, service, or device we want to hear from you. If your vulnerability report affects a product or service that is within the scope of one of our bounty programs below, you may receive a bounty award according to the program descriptions. Even if it is not covered under an existing bounty program, we will publicly acknowledge your contributions when we fix the vulnerability. All vulnerability submissions are counted in our Researcher Recognition Program and leaderboard, even if they do not qualify for the bounty award.

Microsoft Bounty Programs

The Microsoft Bug Bounty Programs are subject to the legal terms and conditions outlined here, and our bounty Safe Harbor policy.

Let the hunt begin!

Our bug bounty programs are divided by technology area though they generally have the same high-level requirements:Research

We want to award youVulnerabilities

We are looking for newdata, privacy, service availability

Avoid harm to customer datavul disclosure

Follow co-ord vulnerability disclosure

You might also like How to Move Windows 10 to SSD (Solid-State Drive)

Cloud Programs

Program NameStart dateLast UpdatedEnd dateEligible entriesBounty Range
Microsoft Azure2014-09-232019-08-05OngoingVulnerability reports on Microsoft Azure cloud servicesUp to $300,000 USD
2018-07-172019-10-23OngoingVulnerability reports on Identity services, including Microsoft Account, Azure Active Directory, or select OpenID standards.Up to $100,000 USD
Xbox2020-01-302020-01-30OngoingVulnerability reports on the Xbox network and servicesUp to $20,000 USD
Microsoft Online Services2014-09-232019-08-05OngoingVulnerability reports on applicable Microsoft cloud services, including Office 365Up to $20,000 USD
Microsoft Azure DevOps Services2019-01-172019-01-17OngoingUp to $20,000 USD
Microsoft Dynamics 3652019-07-172019-07-29OngoingVulnerablility reports on applicable Microsoft Dynamics 365 applicationsUp to $20,000 USD
2016-09-012018-10-16OngoingUp to $15,000 USD

Platform Programs

Program NameStart DateLast UpdatedEnd DateEligible EntriesBounty Range
Microsoft Hyper-V2017-05 -312019-03-15OngoingCritical remote code execution, information disclosure and denial of services vulnerabilities in Hyper-VUp to $250,000 USD
Microsoft Windows Insider Preview2017-07-262020-02-10OngoingCritical and important vulnerabilities in Windows Insider PreviewUp to $30,000 USD
Windows Defender Application Guard2017-07-262017-07-26OngoingCritical vulnerabilities in Windows Defender Application GuardUp to $30,000 USD
Microsoft Edge (Chromium-based)2019-08-202020-01-15OngoingCritical and important vulnerabilities in Microsoft Edge (Chromium-based) Dev, Beta, and Stable channelsUp to $30,000
Microsoft Edge (EdgeHTML) on Windows Insider Preview2016-08-042020-01-232020-03-15Critical remote code execution and design issues in Microsoft Edge (EdgeHTML) in Windows Insider Preview Slow ringUp to $15,000 USD
Office Insider2017-03-152018-12-07OngoingVulnerabilities on Office InsiderUp to $15,000 USD
ElectionGuard2019-10-182019-10-18OngoingVulnerabilities in ElectionGuardUp to $15,000 USD

Defense & Grant Programs

Program NameStart DateLast UpdatedEnd DateEligible EntriesBounty Range
Mitigation Bypass and Bounty for Defense2013-06-262018-10-02OngoingNovel exploitation techniques against protections built into the latest version of the Windows operating system. Additionally, defensive ideas that accompany a Mitigation Bypass submission.Up to $100,000 USD (plus up to an additional $100,000)
Grant: Microsoft Identity2020-01-092020-01-09OngoingThis project grant awards up to $75,000 USD for approved research proposals that improve the security of the Microsoft Identity solutions in new ways for both Consumers (Microsoft Account) and Enterprise (Azure Active Directory).Up to $75,000 USD

Additional resources for security researchers

We have pulled together additional resources to help you understand our bounty program offerings and even help you get started on the path or to higher payouts. We truly view this as a collaborative partnership with the security community. Your success in this program helps further our customer’s security and the ecosystem. Microsoft Bounty Programs

Frequently Asked Questions

Example of High Quality Reports

Microsoft Bounty Legal Safe Harbor

Windows Security Servicing Criteria

Directory of Azure Services

Microsoft Documentation for end-users, developers, and IT professionals

Microsoft Security Research & Defense Blog

HackerOne’s Hacker101 training

Bugcrowd University

Windows Product Key 2023 (Updated) 100% working

Out of Bounty Scope

Some submission types are generally not eligible for Microsoft bounty awards. Please refer to our bounty programs for additional information on eligible submissions, vulnerability, or attack methods. Source

Would you like to read more Microsoft Bounty Programs-related articles? If so, we invite you to take a look at our other tech topics before you leave!

Subscribe To Our Newsletter

Get updates and learn from the best