Policy and restrictions
Preserve customer data and availability; stop on unauthorized access, report immediately and delete retained data. No social engineering, disruptive automation, unauthorized credential use or post-compromise activity. Confidentiality continues through remediation; attack-enabling details wait another 30 days. Imposed remediation deadlines forfeit eligibility. Safe harbor is conditional.
Eligibility and submission status
Participants must be at least 14; minors need guardian permission. Employer, sanctions and public-sector ethics requirements apply; current/recent Microsoft staff and specified related persons are excluded. New, reproducible findings are required.
The policy invites portal submissions but supplies no explicit open/paused status. A visible policy and program listing do not independently establish availability.
Advertised rewards
The introduction and table advertise USD 250–30,000, while award prose starts at USD 500. The lower table value is retained with that discrepancy. Higher discretionary awards are possible; one submission receives its highest qualifying award, not cumulative program payouts.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
Microsoft Edge based on Chromium | product | Dev, Beta and Stable |
WebView2 SDK | software | Prerelease and release |
WebView2 runtime | software | Evergreen, Edge Dev and Beta runtimes |
| Asset | Type | Group / eligibility |
|---|---|---|
Internet Explorer | product | |
Microsoft Edge based on EdgeHTML | product | |
Microsoft Edge Canary-only builds | software | |
Edge training, documentation, sample and community sites | policy_category |
Review limitations
- The program revision history ends April 7, 2026; overarching terms are dated September 3, 2026.
- The Edge page suggests a Standard Award Policy fallback, but that section of the linked Bounty Program Guidelines excludes endpoint/on-premises programs. Fallback eligibility is not assumed.
- Advertised amounts are not individual award evidence. Authenticated submission availability and payment enrollment were not tested.
- Public policy review only. Asset inventories and operational instructions are omitted. Live terms prevail; this summary grants no authorization or legal protection.
Sources and provenance
- Microsoft Edge Bounty Program and revision history Microsoft · reviewed 2026-10-03
- Microsoft Bounty Program Guidelines, terms, safe harbor and Standard Award Policy Microsoft · reviewed 2026-10-03
- Microsoft Security Testing Rules of Engagement Microsoft · reviewed 2026-10-03
- Microsoft Edge Bounty Program Microsoft Corporation · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.