Microsoft adds OneDrive to bug bounty programme
Redmond wants to crowdsource security expertise to make cloud storage more secure

Microsoft has added its cloud storage service, OneDrive, to its bug bounty programme.
It means that security researchers who uncover flaws in the service can get rewards worth anywhere between $500 and $15,000, and Microsoft said it is a sign it is taking cloud security more seriously.
“We continue to add new properties to our security bug bounty programs to help keep our customers secure,” Jason Shirk, senior director of Microsoft Security Response Center wrote on the company’s site, TechNet.
“This addition further incentivizes security researchers to report service vulnerabilities to Microsoft.”
Researchers who discover bugs in XSS, CSRF, injection vulnerabilities, server-side code execution, privilege escalation, and insecure direct object references are eligible for rewards under the programme.
Terry Ip, security consultant at MWR InfoSecurity, said that adding OneDrive to the programme may be “essentially a crowdsourcing effort from the security research community, either in place of or in addition to testing by their security vendor”.
He added: “Whilst the bounty can seem large in some cases, the payout is often lower than the costs involved in employing full-time security researchers.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"One of the key things for security researchers to be aware of is adhering to the scope of the bounty program. Going out of scope could result in legal issues or pay out disputes, despite the good intentions of the researcher.”
The bug bounty programme terms and conditions covering OneDrive can be read here.
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
Future trends, changing work today
whitepaper The Ultimate Guide
By ITPro
-
Go virtual in 3 steps, with Forrester
whitepaper Put virtual reality technology to work in your business
By ITPro
-
VR Diaries: Forrester
Webinar Put virtual reality technology to work in your business
By ITPro
-
Mixed reality for work
whitepaper The ultimate guide
By ITPro
-
Meet in VR: The beginner's guide
whitepaper Seven meeting challenges VR can help you solve
By ITPro
-
Learn in VR: The beginner's guide
whitepaper Seven training challenges VR can help you solve
By ITPro
-
Create in VR: The beginner's guide
whitepaper Five creative challenges VR can help you solve
By ITPro
-
Virtual reality for work: The ultimate guide
whitepaper Six ways virtual reality is changing the future of work
By ITPro