Microsoft is offering security researchers up to $30,000 for discovering critical AI vulnerabilities in Dynamics 365 and Power Platform, emphasizing flaws that could manipulate AI inference or expose information through model behavior.

Vulnerability Category / Focus Area / Impact / Severity / Quality Tier / Maximum Payout / Multiplier / Scope & Qualification Details Inference Manipulation & Disclosure Critical (High / Medium / Low Quality) $30,000 / $20,000 / $12,000 Manipulates model responses or extracts data via model behavior Important AI Vulnerabilities Important (High / Medium / Low Quality) $20,000 / $12,000 / $6,000 High-impact functional or security flaws across AI integrations Remote Code Execution (RCE) Critical Severity Up to $20,000 Code execution flaws across in-scope cloud and service components Cross-Tenant Information Disclosure High-Impact Scenario Up to $20,000 Breaches tenant boundaries to access external organization data Elevation of Privilege / Info Disclosure Critical Severity Up to $12,000 Local and cloud-level unauthorized privilege escalation Dataverse & Sandbox Escapes Special High-Impact Vectors +20% Multiplier Dataverse privilege escalation & Plugin Sandbox host escapes Microsoft requires AI findings to meet its Critical or Important severity definitions and reproduce on the latest, fully patched version of an eligible product.

Microsoft advises marking research tenants with “MSOBB” where possible and following coordinated vulnerability disclosure, ensuring findings reach engineers without exposing customers or production services to risk.