October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Microsoft Paid $16.6 Million in Bug Bounties From July 2023 to June 2024

Microsoft’s $16.6 million bug-bounty figure covered July 2023 through June 2024. The payout increase reflected broader programs in AI, identity, Defender and other high-impact areas—not a universal bounty-rate increase.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft paid $16.6 million to security researchers during its Microsoft Bounty Program year from July 1, 2023, through June 30, 2024. The company said 343 researchers in 55 countries helped identify more than 1,000 potential security issues. The figure was announced on August 5, 2024, and is historical—not Microsoft’s latest published annual total.

Microsoft subsequently reported $17 million distributed in its next published review, so “$16.6 million in the past year” should not be read as a current 2026 figure.

What the $16.6 million figure covers

Microsoft’s annual review covered rewards issued across its bounty programs during the July 1, 2023–June 30, 2024 program year. The company paid 343 researchers located in 55 countries. Microsoft said researchers identified more than 1,000 potential security issues; SecurityWeek reported that Microsoft received more than 1,300 eligible vulnerability reports during the period.

Measure Reported result
Program year July 1, 2023–June 30, 2024
Total rewards $16.6 million
Researchers rewarded 343
Countries represented 55
Potential issues identified More than 1,000, according to Microsoft
Eligible reports More than 1,300, according to SecurityWeek
Largest individual reward $200,000, as reported by SecurityWeek

Microsoft’s announcement is available in its 2024 program review. The report count and $200,000 maximum were reported by SecurityWeek.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was this actually an increase?

Yes, compared with the roughly $13 million per year that SecurityWeek said Microsoft paid from 2020 through 2023. Against a $13 million baseline, $16.6 million is approximately 27.7% higher.

That comparison is directional rather than an audited, identical year-over-year accounting series. It also describes total program spending, not a 27.7% increase for every researcher or every type of vulnerability. Microsoft has not published a universal bounty rate that rose by that percentage.

Why Microsoft’s payouts rose

Microsoft broadened both the number of programs and the attack surfaces it wanted researchers to examine. During the 2023–2024 year, the company highlighted several changes:

  • Launch of the Microsoft AI Bounty Program.
  • Expansion of the Microsoft Identity Bounty Program to include authenticator applications.
  • Expansion of the Microsoft 365 Insider program.
  • Launch of the Microsoft Defender Bounty Program.
  • A Dataverse Integrations Research Grant.
  • A limited-time Windows Secure Boot bounty.
  • Additional Microsoft 365 scenarios involving security-feature bypasses and other high-impact outcomes.

These initiatives focused incentives on cloud services, identity, artificial intelligence, endpoint defense and high-impact security failures. Microsoft did not assign a specific dollar amount to each change, so it is not possible to say how much of the $16.6 million came from any individual program. Broader scope and targeted rewards are the clearest documented reasons the total could rise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Microsoft products are covered?

Microsoft operates separate programs with their own targets and rules. Areas represented in its bounty portfolio include:

  • Azure and other cloud services
  • Microsoft 365
  • Windows
  • Microsoft Edge
  • Dynamics 365
  • Power Platform
  • Microsoft Defender
  • Identity services and authenticator applications
  • Xbox
  • Artificial-intelligence services and related programs

This list does not mean every Microsoft product, configuration or third-party component is automatically eligible. Researchers must check the live Microsoft bounty-program directory for the applicable scope, exclusions, reward range and submission process. Scope can change after an article or older program page was published.

How Microsoft decides what to pay

There is no single Microsoft-wide bounty amount. Each program sets its own award ranges and eligibility rules. Microsoft says evaluations consider:

  • Severity and realistic security impact
  • Completeness and accuracy of the report
  • Reproducibility of the result
  • Whether the finding affects a high-priority security area
  • The product-specific program rules and coordinated-disclosure requirements

A report that is technically interesting but cannot demonstrate a practical impact may receive less, or no, reward. Conversely, a reproducible issue that compromises a high-value security boundary can qualify for a substantially larger payment.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the totals do—and do not—tell you

They are not an average bounty

Dividing $16.6 million by 343 rewarded researchers produces a simple arithmetic ratio of about $48,400 per researcher. That is not an official average: researchers submitted different numbers of reports, and the public total may include grants and different reward categories.

Dividing $16.6 million by more than 1,300 eligible reports produces less than approximately $12,800 per report. This denominator is imprecise because the report count is stated as “more than 1,300,” and an eligible report is not necessarily a paid report. Neither calculation represents a typical Microsoft payout or a guaranteed return for a new researcher.

They do not measure Microsoft’s security quality by themselves

A larger payout total can mean more researchers found reportable issues, more high-impact findings qualified for rewards, or that Microsoft expanded its programs. It does not, by itself, prove that Microsoft’s products became less secure or that a particular number of vulnerabilities existed in production.

The public figures do not show the median payment, the distribution by severity, the percentage of reports that earned money, the number of unique vulnerabilities paid, or the amount spent by each program.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What researchers should check before testing

  1. Confirm the target. Verify that the product, tenant, endpoint or integration appears in the relevant Microsoft program scope.
  2. Read the rules of engagement. Check permitted techniques, rate limits, account requirements, data-handling rules and safe-harbor terms.
  3. Establish real impact. Explain the security boundary crossed and the attacker capabilities required; avoid relying on a purely theoretical scenario.
  4. Use a minimal proof of concept. Demonstrate the issue without accessing unnecessary data, disrupting service or affecting other users.
  5. Make reproduction straightforward. Include versions, configuration details, steps, logs and remediation-relevant evidence.
  6. Check for duplicates and exclusions. A previously known issue, unsupported version, out-of-scope target or third-party defect outside the program’s terms may not qualify.
  7. Submit through Microsoft’s process. Follow the program’s coordinated vulnerability disclosure instructions rather than publishing details immediately.

Following these steps improves triage quality but cannot guarantee payment. A large annual program total is an aggregate across many researchers, severity levels, grants and products—not a promise that an individual submission will receive a large award.

How coordinated disclosure fits the program

Microsoft uses coordinated vulnerability disclosure: a researcher privately reports a suspected issue, Microsoft investigates and remediates it, and disclosure is coordinated rather than immediate. A bounty is therefore not permission to test any Microsoft system in any manner.

Testing must remain within the relevant scope and rules, including restrictions on service disruption, personal-data handling and unauthorized access. Microsoft’s program directory is the controlling source for current requirements.

The next published year reached $17 million

In its next year-in-review, dated August 5, 2025, Microsoft said it distributed $17 million to 344 researchers from 59 countries and identified more than 1,000 potential vulnerabilities. That update puts the $16.6 million result in context: it was a significant 2023–2024 total, but not the endpoint of Microsoft’s published bounty spending.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s follow-up announcement is available at Microsoft’s 2025 year-in-review. Secondary reports in 2026 have described totals above $20 million, but without the underlying Microsoft announcement those figures should be treated as reported rather than independently verified.

Status of the $16.6 million headline

Status: The $16.6 million figure is accurate for Microsoft’s July 1, 2023–June 30, 2024 bounty-program year. Microsoft later reported $17 million for the following published year. Anyone seeking a current 2026 total should rely on the latest primary announcement from Microsoft’s Security Response Center, not on the older “past year” wording.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.