Microsoft launches Identity Bounty program that offers bug bounty hunters up to $100,000. For security researchers who discover a security vulnerability in the Identity services would payout between $500 to $100,000.
A Bug bounty program is also known as vulnerability rewards program (VRP) is the one where security researchers can disclose vulnerabilities and can receive recognition and compensation for reporting bugs. Bug bounty program is suitable for organizations of all sizes; it is a part of the organization’s penetration testing plan.
Microsoft said we have invested heavily in the security and privacy of both our consumer and enterprise identity solutions. For security researchers who find the vulnerability in the Identity services can report to Microsoft privately.
“Submissions for standards protocol or implementation bounties need to be with a fully ratified identity standard in the scope of this bounty and have discovered a security vulnerability with the protocol implemented in our certified products, services, or libraries.”
login.windows.net
login.microsoftonline.com
login.live.com
account.live.com
account.windowsazure.com
account.activedirectory.windowsazure.com
credential.activedirectory.windowsazure.com
portal.office.com
passwordreset.microsoftonline.com
Microsoft Authenticator (iOS and Android applications)*
A high-quality report background information, a description of the bug, and a proof of concept would receive bounty Up to $100,000, Baseline Quality Submissions would receive bounty Up to $50,000 and for Incomplete Submissions, bounty starts from $500.
Intel Expands Bug Bounty Program Rewards To $250,000 for Meltdown and Spectre Like Vulnerabilities
Bug Bounty Researchers Make More than 2.7 Times Salary of an Average Software Engineer
Facebook Launches Data Abuse Bounty Program With rewards Up to $40,000
Multinational engineering and technology services firm Tata Technologies has reportedly fallen victim to a significant…
U.S. authorities announced the seizure of $31 million tied to the 2021 Uranium Finance decentralized…
Imagine a government that tracks your daily movements, monitors your communications, and catalogs your digital…
A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt sensitive…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows privilege…
Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…