What network type are you using (flat, vlan, tunnels)? That config looks fine. You're using Hyper-V switch ACLs on the Hyper-V side and iptables on the controller for the security groups.

So, since the dnsmasq part is ok, I'd check the dhcp namespace on the controller. You may check if the DHCP requests get there as well. Also, make sure that you don't have other DHCP servers replying to your requests.

Regards, Lucian