TH is using products below Windows Server 2016, which are in Extended or End-of-Support (EOL/EOS) status?

Cyrus Vo (WICLOUD CORPORATION) 0 Reputation points Microsoft External Staff
2025-11-27T11:43:14.4633333+00:00

What are the commitments from MS for the paid support program if there are cyber security incidents that occurred with the use of outdated products? 

Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 68,145 Reputation points MVP Volunteer Moderator
    2025-11-27T12:09:49.63+00:00

    Microsoft’s commitments in paid support programs during cybersecurity incidents involving outdated or end-of-support products are limited but predictable. In these situations Microsoft will still provide incident-response assistance, but only on a best-effort basis. This means support engineers can help investigate abnormal behavior, review logs, recommend containment steps, and offer remediation guidance using whatever diagnostic tools and documentation remain available for the legacy product. Customers continue to have access to support engineers, escalation resources, and account managers included in their specific support contracts, but the effectiveness of this help is constrained by the fact that the product is no longer maintained.

    Microsoft may also provide existing knowledge articles, previously released patches, and general hardening or configuration guidance. Support teams can help interpret these materials and recommend compensating controls. In some cases, and only when a customer has purchased a separate Custom Support Agreement, Microsoft may develop paid security hotfixes for products that are out of support. These agreements are negotiated individually, apply only to specific classes of products, and are not part of standard Unified or Premier Support.

    There are also clear limitations. Without a Custom Support Agreement Microsoft does not create new patches, code fixes, or updates for unsupported products, and there is no guarantee that the incident can be resolved. Support is provided as guidance rather than a commitment to eliminate threats or fully restore affected systems. Microsoft also disclaims liability for security incidents or damages resulting from the continued use of outdated software, even when the customer has an active paid support contract. These boundaries are reflected in Microsoft’s Product Terms, service agreements, lifecycle policies, and the contracts governing Unified Support, Premier Support, and Custom Support programs.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.