Overview
- Microsoft is accepting vulnerability submissions from August 4 through October 4, 2025, for Azure, Copilot, Dynamics 365, Power Platform, Identity and M365 in the Zero Day Quest 2026 research challenge.
- The program offers up to $5 million in total rewards and applies a 50% bounty multiplier for critical-severity vulnerabilities and high-impact scenarios.
- Over the past year, Microsoft’s bug bounty programs paid a record $17 million to 344 security researchers across 59 countries for 1,469 validated reports.
- Bounty coverage has expanded to include Copilot AI services, Microsoft Defender products and additional identity management systems.
- Top performers will earn invitations to an invite-only live hacking event at Microsoft’s Redmond campus in spring 2026 to collaborate directly with MSRC and product teams.