How is Power Platform security tested?

Have you ever wondered how Microsoft Power Platform is security tested @Microsoft?

Have you ever wondered how Microsoft Power Platform is security tested @Microsoft? 2 great places can give you some ideas: - Service Trust Portal which among resources such as safety Certifications, Standards, and Disaster policies, contains a series of reports on Penetration Tests and Security Assessments for most of the Microsoft cloud Components such as **#Office365**, **#Dynamics365**, **#Windows**, or **#Azure**. Those reports follow the **#OWASPTop10** web application security risks classification and can give an insight into how often such a big cloud requires security updates! In the last two months, 6 such reports were shared publicly. - Microsoft Bug Bounty Program is a program for security researchers in which reporting a security vulnerability can be rewarded with up to $100,000 USD for a loophole found in Microsoft Identity and up to $20,000 USD for **#PowerPlatform** and **#Dynamics365**. Currently, the most rewarded scenarios for Power Platform are Cross-tenant information disclosure and escalation of **#Dataverse** privileges. Do you know any other good places that touch on this topic? Does it make you more comfortable thinking about whether this low-code tool is secure? Links to both portals in the comments! ___ - Service Trust Portal - Penetration Test and Security Assessments: https://servicetrust.microsoft.com/viewpage/PenTest - Microsoft Dynamics 365 and Power Platform Bounty Program: https://www.microsoft.com/en-us/msrc/bounty-dynamics
Browse articles