Unable to Create Azure Support Request for Ransomware Incident - Need Microsoft Security Assistance

Ranjitha NJ 0 Reputation points
2026-08-31T09:28:01.0333333+00:00

Hello Team,

We are experiencing a ransomware/security incident in our environment.

Our requirement is to engage Microsoft Security/Azure support to perform:

  1. Deep Microsoft Defender investigation.
  2. Security assessment of affected endpoints and servers.
  3. Threat hunting and forensic analysis.
  4. Verification of ransomware impact across Azure resources.

However, when we try to create a support request from the Azure Portal (Help + Support), we are redirected to Microsoft Q&A and are unable to open a support case.

Could you please advise:

  • How to engage Microsoft Security support for a ransomware incident?
  • Whether there is an alternative escalation path?
  • What permissions or support-plan requirements should be verified to enable support ticket creation?

Environment:

  • Azure Subscriptions
  • Microsoft Defender

Thank you.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Most helpful
  1. Chris Hailes 155 Reputation points MVP
    2026-09-04T23:30:08.87+00:00

    The 30-day security-info replacement period is an account-protection measure. An expired “Replace security info” link does not, by itself, confirm whether the replacement completed or whether a new 30-day waiting period has started.

    To check the current status, do not continue using old email links. Instead, open Microsoft’s account security page directly:

    https://account.microsoft.com/security

    After signing in, select Manage how I sign in and check whether the replacement security information is now listed. Do not submit another replacement request until you know whether an existing request is still pending.

    If Microsoft shows “Your security info change is still pending,” follow the options displayed on that page. If you recognize the request and still have access to the previous security information, Microsoft may provide an option to cancel it. If you did not request the change, or the activity is unfamiliar, use the “let us know” option rather than cancelling it.

    For sign-in problems, use Microsoft’s official Sign-in Helper:

    https://aka.ms/sign-in-helper

    If the security page does not show the status clearly, contact Microsoft Support and ask them to review whether the original replacement completed, whether a replacement request is still pending, and whether another 30-day period has been started. Include the affected account alias, the date of the “waiting period is over” email, the exact error message, and the date the link was used. Ask Support to confirm the correct next step before submitting another replacement request.

    Microsoft Support may be limited in its ability to bypass account-security protections or manually change security information, so do not assume that an expired link can be refreshed or that the waiting period can be shortened. The account-security page and Support are the appropriate channels to confirm the account’s state.

    For your privacy, do not post recovery addresses, full email headers, subscription IDs, or account screenshots on Microsoft Q&A. If a screenshot is requested, redact email addresses, account aliases, codes, tokens, and subscription details.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.