# Setting up CUBE as a Microsoft Teams Direct Routing SBC

Systems: Cisco Unified Border Element

For Voice engineers configuring CUBE to pair with Microsoft Teams Direct Routing.

Canonical: https://warmtransfer.net/guides/cube-teams-direct-routing-setup

Last verified: 2026-09-30

Direct Routing connects a certified session border controller to [Microsoft Teams Phone](https://warmtransfer.net/knowledge/microsoft-teams-phone) over SIP/TLS and SRTP[^65][^66]. This guide walks through configuring Cisco Unified Border Element (CUBE) and pairing it as an online PSTN gateway in Microsoft Teams[^13][^44].

## Before you start

- Direct Routing requires a Microsoft-certified SBC, PSTN trunks connected to it, users homed online, a public IP address, an SBC FQDN in a verified tenant domain (not `*.onmicrosoft.com`) with public DNS, and a publicly trusted TLS certificate[^66].
- Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used[^67].
- Users must be licensed with Teams Phone and have a PSTN solution[^68].
- Direct Routing is not supported in Islands coexistence mode[^69].

## What changes by situation

- Which SBC will terminate Direct Routing? Cisco Unified Border Element; Another certified SBC.
- Will the trunk use media bypass? Media bypass disabled; Media bypass enabled.
- Which Microsoft cloud is the tenant in? Microsoft 365, Office 365, or GCC; Office 365 GCC High; Office 365 DoD.

## Step 1: Confirm the SBC and its software are certified

**Cisco Unified Border Element**

### Do
Microsoft lists Cisco Unified Border Element as certified for Direct Routing, both non-media bypass and media bypass, on 1000 Series ISR, 4000 Series ISR, CSR 1000V, ASR 1000 and Catalyst 8000 Edge platforms[^13]. Cisco Unified Border Element is supported from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge), with 17.6.1a recommended (17.3.3 recommended for CSR 1000V)[^23]. Higher firmware versions are supported as long as the major.minor version matches a documented version[^9]. Note that CUBE rows are marked 911 Service Provider capable but not ELIN capable, and Cisco does not appear in the Local Media Optimization support table[^17].

### Verify
Suggested check: Run `show version` on the router and confirm the running release satisfies the platform requirements. Escalating an SBC issue to Microsoft requires presenting the SBC vendor's investigation report with a ticket reference[^63].

### Rollback
Suggested rollback: Downgrade or upgrade the platform firmware to an approved certified release before continuing.

**Another certified SBC**

### Do
Confirm that your third-party SBC model and firmware version appear on Microsoft's certified list[^67][^9]. Microsoft supports higher firmware versions as long as the major.minor version matches a documented version[^9].

### Verify
Suggested check: Check the administration page to confirm the running major.minor release matches the certified list.

### Rollback
Suggested rollback: Apply a certified firmware release per your vendor's instructions before proceeding.

## Step 2: Prepare the SBC FQDN, tenant domain, and DNS

### Do
The SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant other than `*.onmicrosoft.com`, and any subdomain used in the FQDN must itself be registered[^34]. Ensure that the tenant contains a user in the SBC's domain with an assigned E3 or E5 license, and that the domain's authentication type is Managed[^33]. Create a public DNS A record resolving the FQDN to the SBC public IP address[^66]. Direct Routing does not support mapping multiple IP addresses to the same FQDN on the SBC side[^47].

### Verify
Suggested check: Query public DNS for the SBC FQDN to ensure it returns a single public IP address, and confirm the domain is registered and verified.

### Rollback
Suggested rollback: Remove the public DNS record for the SBC FQDN.

## Step 3: Open the firewall for signaling and media to Microsoft

**Microsoft 365, Office 365, or GCC**

### Do
Allow SIP/TLS from the SBC to the Microsoft SIP proxy on destination port 5061, and allow SIP/TLS from the Microsoft SIP proxy (source ports 1024-65535) to the port configured on the SBC[^58]. Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and Microsoft requires allowing signaling to and from all of these ranges rather than only the addresses DNS returns[^57]. For media between Microsoft media processors and the SBC, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions[^70]. Microsoft recommends at least 2 media ports per concurrent call on the SBC[^70]. Sources disagree on the media processor ranges for commercial clouds: the Plan Direct Routing page specifies both 52.112.0.0/14 and 52.120.0.0/14, while the media bypass planning page lists only 52.112.0.0/14[^41][^40].

### Verify
Suggested check: Validate outbound TCP connectivity on the signaling port to the primary SIP destination.

### Rollback
Suggested rollback: Remove the firewall rules allowing signaling and media traffic to the cloud provider.

**Office 365 GCC High**

### Do
Allow SIP/TLS signaling on port 5061 from the SBC to Microsoft, and from Microsoft source ports 1024-65535 to the configured SBC port[^58]. GCC High uses the single Direct Routing FQDN `sip.pstnhub.gov.teams.microsoft.us` and IP range 52.127.88.0/21, with no secondary or tertiary FQDNs[^36]. For media, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions with at least 2 media ports per concurrent call on the SBC[^70].

### Verify
Suggested check: Validate outbound TCP connectivity on the signaling port to the designated government FQDN.

### Rollback
Suggested rollback: Remove the firewall access rules for the government signaling and media destinations.

**Office 365 DoD**

### Do
Allow SIP/TLS signaling on port 5061 from the SBC to Microsoft, and from Microsoft source ports 1024-65535 to the configured SBC port[^58]. DoD uses the single Direct Routing FQDN `sip.pstnhub.dod.teams.microsoft.us` and IP range 52.127.64.0/21, with no secondary or tertiary FQDNs[^36]. For media, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions with at least 2 media ports per concurrent call on the SBC[^70].

### Verify
Suggested check: Validate outbound TCP connectivity on the signaling port to the designated defense FQDN.

### Rollback
Suggested rollback: Remove the firewall access rules for the defense signaling and media destinations.

## Step 4: Open client and relay media paths for bypass

**Media bypass disabled**

### Do
Maintain direct media processor firewall rules only, as media bypass is disabled[^70].

### Verify
Suggested check: Confirm firewall rules do not allow client-to-SBC direct UDP media ports.

### Rollback
Suggested rollback: No configuration change required.

**Media bypass enabled**

### Do
Ensure Teams clients can reach the SBC's public IP address via UDP/SRTP from client ports 50000-50019 to the ports defined on the SBC, and back[^3]. Allow Teams Transport Relays to send from ports 50000-59999 to the SBC, and allow the SBC to reach relays on ports 50000-59999 and 3478-3481[^7]. Keep media processor ports open, as media processors stay in the path for voice applications (call park, auto attendants, call queues), web clients, escalations to group calls, calls to federated Teams users, and transfers to Skype for Business users[^5]. Do not use IPv6, because media bypass is not supported when IPv6 is used for SIP, media, or the Teams client[^39].

### Verify
Suggested check: Test UDP reachability between internal test client subnets and the SBC public IP address on the designated media ports.

### Rollback
Suggested rollback: Remove the client port range and Transport Relay firewall rules.

## Step 5: Install the public certificate and trust Microsoft's roots

**Cisco Unified Border Element**

### Do
Generate an RSA key pair and a `crypto pki trustpoint` on CUBE with `rsakeypair`, `fqdn`, `subject-name` CN, `subject-alt-name`, `enrollment terminal`, and revocation-check settings[^30]. Generate the CSR on the SBC, ensure the certificate carries the SBC FQDN as CN or SAN, have it signed by a CA in the Microsoft Trusted Root Program, include the Server Authentication EKU, and note that RFC 2818 wildcards are supported[^8]. Microsoft SIP endpoints currently accept SBC certificates without the Client Authentication EKU[^10]. Import Microsoft's 7 root CAs into the trust store for both client and server certificates: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root Certificate Authority 2017, and Microsoft RSA Root Certificate Authority 2017[^56]. Microsoft states that Direct Routing SIP endpoint certificates issued by a new CA were rolled out in production at the end of July 2026[^43].

### Verify
Suggested check: Run `show crypto pki certificates` on CUBE and verify the installed SBC certificate contains the SBC FQDN in the CN or SAN, and verify all root CAs appear in the trust store.

### Rollback
Suggested rollback: Remove the trustpoint and delete the certificate and key pair with `no crypto pki trustpoint <name>`.

**Another certified SBC**

### Do
Generate a CSR directly on the SBC, ensuring the SBC FQDN is present in the CN or SAN, that it is signed by a CA in the Microsoft Trusted Root Program, and that it includes the Server Authentication EKU[^8]. Import all 7 Microsoft root CAs into the SBC root store for both client and server certificate validation[^56]. Microsoft SIP endpoints currently accept certificates without the Client Authentication EKU[^10].

### Verify
Suggested check: Inspect the certificate management tab on the SBC to confirm the installed identity certificate matches the SBC FQDN and that all designated root CAs are trusted.

### Rollback
Suggested rollback: Delete the installed certificate and private key using the vendor management interface.

## Step 6: Enforce TLS 1.2 and SRTP toward Teams

**Cisco Unified Border Element**

### Do
Under `sip-ua`, enforce TLS 1.2 using `transport tcp tls v1.2` as the minimum version[^28]. Define the cipher suite under a `voice class tls-cipher` and bind the trustpoint and cipher in a `voice class tls-profile`[^28]. Microsoft forces TLS 1.2 and requires connecting with 1 of 4 ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256[^61]. Configure SRTP using `voice class srtp-crypto`[^25]. WarmTransfer's reading of the sources is that because Microsoft's example Teams-to-SBC offer uses RTP/SAVP with `a=crypto AES_CM_128_HMAC_SHA1_80`, the SBC leg toward Teams is SRTP with SDES keys[^59]. Apply SRTP globally under `voice service voip sip`, in a `voice class tenant`, or on the dial-peer with `voice-class sip srtp-crypto`, and enable secure calls on the dial-peer using `srtp`[^25].

### Verify
WarmTransfer's reading of the sources is that the administrator must confirm from the TLS connection detail that the negotiated suite is 1 of the 4 suites Microsoft accepts[^14]. Run `show sip-ua connections tcp tls brief` or `show sip-ua connections tcp tls detail` to verify active TLS connections[^29]. Run `show sip-ua calls` to display local and remote crypto keys to confirm SRTP negotiation[^26].

### Rollback
Suggested rollback: Remove the `voice class tls-profile`, `voice class tls-cipher`, and `voice class srtp-crypto` configurations from CUBE.

**Another certified SBC**

### Do
Configure TLS 1.2 on the SBC SIP profile using 1 of Microsoft's 4 approved ECDHE-RSA ciphers: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256[^61]. Enable SRTP toward Microsoft Teams[^66].

### Verify
Suggested check: Check the SBC connection monitoring dashboard to verify the configured secure transport is negotiated and that active sessions show media encryption.

### Rollback
Suggested rollback: Revert TLS and SRTP settings in the SBC vendor management interface.

## Step 7: Build the Teams tenant and SIP header handling on CUBE

**Cisco Unified Border Element**

### Do
Create a `voice class tenant` template for the Teams trunk; CUBE resolves settings in the order of dial-peer, then tenant, then global[^27]. In the tenant, configure `session transport tcp tls`, `listen-port secure`, and apply the `voice class tls-profile`[^28]. Direct Routing requires every OPTIONS and INVITE sent to Teams to carry the paired SBC FQDN in the Contact header, refusing an IP address with 403 Forbidden[^12]. Direct Routing matches the FQDN in Contact against the certificate's CN or SAN and uses that FQDN or parent domain to identify the tenant[^11]. Configure a `voice class sip-profiles` rule to modify or insert the SBC FQDN into the Contact header if needed, noting that outbound profiles apply via `voice-class sip profiles` on a dial-peer while inbound profiles require `sip-profiles inbound`[^24]. Ensure phone numbers in the Request-URI and From header carry a leading plus sign in +E.164 format, and add `user=phone` to the Request-URI as Microsoft recommends[^50]. Send early offer INVITEs with SDP, as Direct Routing does not support Delayed Offer INVITEs and does not support SIPS URIs[^45].

### Verify
Suggested check: Enable `debug ccsip feature sip-profiles` or run a SIP packet capture to verify that outgoing OPTIONS and INVITE messages carry the SBC FQDN in the Contact header with `transport=tls` and that phone numbers in the Request-URI carry a leading plus sign[^24][^12][^50].

### Rollback
Suggested rollback: Remove the `voice class tenant` and `voice class sip-profiles` from CUBE.

**Another certified SBC**

### Do
Configure your SBC SIP profile to ensure the Contact header in all outbound OPTIONS and INVITE requests carries the paired SBC FQDN rather than an IP address[^12]. Direct Routing matches this FQDN against the certificate and uses it to find the tenant[^11]. Format Request-URI and From numbers with a leading plus sign (+E.164), append `user=phone` to the Request-URI, and ensure calls use early offer with SDP, avoiding Delayed Offer and SIPS URIs[^50][^45].

### Verify
Suggested check: Capture a SIP trace on the SBC to verify that Contact headers present the SBC FQDN, Request-URIs include `user=phone` and a leading plus sign, and initial INVITEs include SDP.

### Rollback
Suggested rollback: Revert SIP header manipulation profiles on the SBC.

## Step 8: Configure the OPTIONS keepalive toward Teams

**Cisco Unified Border Element**

### Do
Configure a `voice class sip-options-keepalive` profile with `transport tcp tls`[^21]. Direct Routing requires SIP OPTIONS from the SBC to be sent no more often than once every 60 seconds and no less often than once every 180 seconds per trunk per endpoint[^48]. The CUBE default `up-interval` is 60 seconds, which satisfies this requirement[^21]. When Direct Routing receives incoming OPTIONS from an SBC, it starts sending its own OPTIONS to the SBC FQDN given in the Contact header of those incoming OPTIONS[^49]. Attach the keepalive profile to the Teams dial-peer using `voice-class sip options-keepalive profile <id>`[^21].

### Verify
Run `show voice class sip-options-keepalive <id>`, `show dial-peer voice summary`, and `show dial-peer voip keepalive status <tag>` to verify keepalive state[^20]. When keepalive fails for every destination in a dial-peer, CUBE marks that dial-peer inactive (busyout)[^20].

### Rollback
Suggested rollback: Remove `voice-class sip options-keepalive profile` from the dial-peer and delete the `voice class sip-options-keepalive` profile.

**Another certified SBC**

### Do
Enable SIP OPTIONS keepalive pings on the SBC toward Microsoft Direct Routing, setting the ping frequency to an interval between 60 and 180 seconds[^48]. Direct Routing will send its own OPTIONS to the FQDN received in your SBC's Contact header[^49].

### Verify
Suggested check: Review the SBC status page to confirm that outgoing OPTIONS receive successful responses.

### Rollback
Suggested rollback: Disable SIP OPTIONS pings on the SBC trunk profile.

## Step 9: Build dial-peers to Teams and to the carrier

**Microsoft 365, Office 365, or GCC**

### Do
On CUBE, create a `voice class server-group` containing `sip.pstnhub.microsoft.com`, `sip2.pstnhub.microsoft.com`, and `sip3.pstnhub.microsoft.com` in that priority order[^71]. Configure an outbound SIP dial-peer referencing the server group via `session server-group`, applying `voice-class sip tenant`, the options-keepalive profile, and bind interfaces[^16]. Configure inbound dial-peer matching with `incoming uri`[^16]. Configure codecs supported by Direct Routing: SILK, G.711, G.722, G.729, or AMR-WB (AMR-WB is supported only without media bypass)[^72]. Configure CUBE to stop retrying on a 603 response, otherwise a user who declines a call sees several missed calls[^1]. Configure carrier-facing dial-peers for PSTN connectivity[^66].

### Verify
Run `show dial-peer voice summary` to confirm dial-peers are active and operational[^20].

### Rollback
Suggested rollback: Remove or shut down the outbound and inbound dial-peers configured for Direct Routing.

**Office 365 GCC High**

### Do
On CUBE, configure an outbound SIP dial-peer referencing a `voice class server-group` containing the single FQDN `sip.pstnhub.gov.teams.microsoft.us`[^36][^16]. Apply the `voice-class sip tenant`, options-keepalive profile, and bind interfaces[^16]. Configure inbound matching using `incoming uri`[^16]. Configure codecs supported by Direct Routing (SILK, G.711, G.722, G.729, or AMR-WB without bypass)[^72]. Configure CUBE to stop retrying on a 603 response[^1]. Configure carrier-facing dial-peers[^66].

### Verify
Run `show dial-peer voice summary` to confirm the dial-peers are active and operational[^20].

### Rollback
Suggested rollback: Remove or shut down the GCC High dial-peers on CUBE.

**Office 365 DoD**

### Do
On CUBE, configure an outbound SIP dial-peer referencing a `voice class server-group` containing the single FQDN `sip.pstnhub.dod.teams.microsoft.us`[^36][^16]. Apply `voice-class sip tenant`, the options-keepalive profile, and bind interfaces[^16]. Configure inbound matching using `incoming uri`[^16]. Configure codecs supported by Direct Routing (SILK, G.711, G.722, G.729, or AMR-WB without bypass)[^72]. Configure CUBE to stop retrying on a 603 response[^1]. Configure carrier-facing dial-peers[^66].

### Verify
Run `show dial-peer voice summary` to confirm the dial-peers are active and operational[^20].

### Rollback
Suggested rollback: Remove or shut down the DoD dial-peers on CUBE.

## Step 10: Pair CUBE as an online PSTN gateway in Teams

**Media bypass disabled**

### Do
Pair the SBC either in the Teams admin center under **Voice** > **Direct Routing** > **SBCs** > **Add**, or by running PowerShell `New-CsOnlinePSTNGateway -Fqdn <SBC-FQDN> -SipSignalingPort <port> -MaxConcurrentSessions <number> -Enabled $true`[^44]. For GCC High and DoD clouds, PowerShell must be used because the option is not available in the Teams admin center[^37]. Leave `SendSIPOptions` set to True (the default), as turning it off excludes the SBC from monitoring and alerting[^55]. Keep `MediaBypass` disabled ($false)[^4].

### Verify
Run `Get-CsOnlinePSTNGateway` and confirm the SBC is listed with `Enabled` True[^64]. Validate that the SBC receives 200 OK to its outgoing OPTIONS and answers Direct Routing's incoming OPTIONS with 200 OK[^64]. In the Teams admin center health dashboard, confirm TLS connectivity status is active and SIP options status is Active[^32][^31].

### Rollback
Set `Enabled` to false using `Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -Enabled $false` to take the SBC out of service, or remove it with `Remove-CsOnlinePSTNGateway`[^55].

**Media bypass enabled**

### Do
Pair the SBC in Teams using `New-CsOnlinePSTNGateway` or the Teams admin center, then enable bypass using `Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -MediaBypass $true`[^44][^4]. For GCC High and DoD clouds, use PowerShell because pairing is not available in the Teams admin center[^37]. On CUBE, configure `voice class stun-usage <tag>` with `stun usage ice lite`, and apply it to the Teams dial-peer with `voice class stun-usage`[^18][^16]. Ensure unsupported ICE-Lite features are not enabled: Cisco lists IPv6, ANAT, codec transparent, SDP passthrough, media flow-around, MTP, and TCL/VXML scripts as unsupported with ICE-Lite[^18]. Ensure the SBC handles REFER, which is mandatory for media bypass certification, as transfer without SBC REFER handling is not supported in media bypass mode[^51]. The SBC must also support ICE restarts when calls are transferred to endpoints that do not support media bypass[^38]. To pilot bypass, Microsoft describes configuring a second trunk FQDN on the same SBC with media bypass enabled, a different TLS signaling port, the same media ports, a certificate covering both names, and a separate voice routing policy[^6].

### Verify
Confirm pairing via `Get-CsOnlinePSTNGateway` with `Enabled` True and successful 200 OK OPTIONS responses in both directions[^64]. Verify ICE-Lite on CUBE using `show voip ice summary`, `show voip ice instance call-id <id>`, `show voip ice global-stats`, or `show voip rtp connections`[^19].

### Rollback
Run `Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -MediaBypass $false` and remove the `stun-usage` class from the Teams dial-peer[^4][^16].

## Step 11: Configure voice routing in Teams

### Do
Configure call routing elements in PowerShell using `Set-CsOnlinePstnUsage` to add a usage, `New-CsOnlineVoiceRoute` with `-NumberPattern`, `-OnlinePstnGatewayList` and `-OnlinePstnUsages`, `New-CsOnlineVoiceRoutingPolicy`, and `Grant-CsOnlineVoiceRoutingPolicy`[^53]. Do not edit the global (org-wide default) online voice routing policy to add the Direct Routing usage, as it applies to all voice-enabled users and can route Calling Plan and Operator Connect users' calls to the Direct Routing trunk[^35]. Direct Routing evaluates PSTN usages in order and the first match wins, while SBCs within a single voice route are tried in random order[^54].

### Verify
Verify policy assignment by running `Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy`[^53].

### Rollback
Suggested rollback: Run `Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null` to remove the custom routing policy from test users, then delete the voice route and PSTN usage.

## Step 12: Enable pilot users with Direct Routing numbers

### Do
Assign each pilot user a phone number using `Set-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting` (or configure it on the user's page in the Teams admin center), which also enables Enterprise Voice[^2]. Microsoft recommends using full E.164 format[^2]. Ensure the users are in Teams Only mode (`UpgradeToTeams` instance of `TeamsUpgradePolicy`) so incoming calls land in the Teams client[^60].

### Verify
Suggested check: Check the user details in the administration portal under user management to confirm the assigned telephone number is listed with type Direct Routing.

### Rollback
Suggested rollback: Remove the phone number assignment in the administration portal.

## Step 13: Test calls end to end

### Do
Execute Microsoft's post-configuration validation checklist: verify a healthy SBC connection, place inbound and outbound PSTN calls, test emergency calling if configured, verify failover between SIP connection points, confirm voice routing policy assignment, and assess call quality[^62]. Test call transfers, noting that if the SBC advertises REFER in its Allow header, Direct Routing sends REFER for transfers[^51]. Reject an incoming test call to confirm the SBC stops retrying after receiving a 603 response[^1]. Direct Routing requires specific emergency call routing policies, unlike carrier-managed PSTN models where the carrier handles emergency routing[^73]. Note that Direct Routing does not support media re-targeting: if the SBC signals a new media IP address mid-call, Direct Routing never sends media to the new address[^46].

### Verify
On CUBE, run `show sip-ua calls` to inspect the local and remote crypto keys and confirm SRTP media encryption on the call[^26]. When evaluating the Direct Routing health dashboard, note that the network effectiveness ratio counts answered, busy, ring-no-answer, and terminal-reject calls as delivered, and with fewer than 100 calls analysed, a low ratio can still be normal[^42].

### Rollback
Suggested rollback: Investigate failed calls by inspecting SIP traces on CUBE and review dial-peer matching and firewall logs.

## Step 14: Hand over monitoring and support

### Do
Monitor the Direct Routing health dashboard in the Teams admin center (**Voice** > **Direct Routing**)[^32]. The dashboard displays per-SBC TLS connectivity status and warns when an SBC certificate will expire within 30 days[^32]. Track the dashboard's SIP options status: it displays Active when OPTIONS flow regularly, 'Warning, no SIP options' when a configured SBC's OPTIONS were never seen, and 'Warning, SIP Messages aren't configured' when OPTIONS monitoring is off[^31]. Document the operational support process: to escalate an SBC-related Direct Routing issue to Microsoft, first open a ticket with the SBC vendor and obtain their investigation report and ticket reference, as Microsoft requires the vendor's report before escalating[^63].

### Verify
Check the Teams admin center Direct Routing dashboard to confirm the SBC status is Active with no TLS or SIP options warnings[^31].

### Rollback
Suggested rollback: No ongoing rollback needed for monitoring setup.

## Applicability

Applies to: Microsoft Teams Phone and Cisco Unified Border Element. Deployments: on-premises, multi-tenant, dod, gcc, and gcc-high. Sources checked 2026-09-30. Microsoft lists CUBE as supported starting from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge), with 17.6.1a recommended (17.3.3 recommended for CSR 1000V)[^23]. GCC High uses sip.pstnhub.gov.teams.microsoft.us and DoD uses sip.pstnhub.dod.teams.microsoft.us, where pairing must be completed with PowerShell rather than the Teams admin center[^36][^37].

## What remains uncertain

Sources disagree on the media processor IP ranges for commercial Microsoft 365 and Office 365 environments: the Plan Direct Routing documentation specifies both 52.112.0.0/14 and 52.120.0.0/14, whereas the media bypass planning documentation lists only 52.112.0.0/14[^41][^40]. In addition, sources disagree regarding SIP Replaces handling: Microsoft's SIP protocol documentation states that Direct Routing rejects SIP requests carrying a Replaces header, while also stating elsewhere on the same page that the SBC must support INVITE with Replaces[^52]. Exact PowerShell syntax for unassigning Direct Routing phone numbers was not covered by the sources below.

## Sources

[^1]: The SBC must be configured to stop retrying on a 603 response; otherwise a user who declines a call sees several missed calls. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Handling retries (603 response). Checked 2026-09-30.
[^2]: A Direct Routing number is assigned with Set-CsPhoneNumberAssignment -PhoneNumber <number> -PhoneNumberType DirectRouting (or in the Teams admin center user page), which also enables Enterprise Voice; Microsoft recommends full E.164 format. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice. Checked 2026-09-30.
[^3]: For direct bypass media, Teams clients must reach the SBC's public IP: UDP/SRTP from client ports 50000-50019 to ports defined on the SBC, and back. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Requirements for direct media traffic (between the Teams client and the SBC). Checked 2026-09-30.
[^4]: Media bypass keeps media between the SBC and the Teams client using ICE on the client and ICE Lite on the SBC, is set per SBC with Set-CsOnlinePSTNGateway -MediaBypass, and signaling still always flows through the Microsoft cloud. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), About media bypass with Direct Routing; Call flow if the user has direct access to the public IP address of the SBC. Checked 2026-09-30.
[^5]: Even on a media bypass trunk, Microsoft media processors stay in the path for voice applications (call park, auto attendants, call queues), web clients, escalations to group calls, calls to federated Teams users and transfers to Skype for Business users. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Use of Media Processors and Transport Relays; Use of Teams Media Processors if trunk is configured for media bypass; Requirements for using media processors. Checked 2026-09-30.
[^6]: To pilot media bypass, Microsoft describes a second trunk FQDN on the same SBC with media bypass enabled, a different TLS signaling port, the same media ports, a certificate covering both names, and a separate voice routing policy for the test users. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Configure separate trunks for media bypass and non-media bypass. Checked 2026-09-30.
[^7]: With media bypass, Teams Transport Relays send from ports 50000-59999 to the SBC, and the SBC must be able to reach relays on 50000-59999 and 3478-3481 because two relay versions are in use. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Requirements for using Transport Relays, port table and note. Checked 2026-09-30.
[^8]: Microsoft recommends generating the SBC certificate from a CSR on the SBC; the certificate should carry the SBC FQDN as CN or SAN, be signed by a CA in the Microsoft Trusted Root Program and include the Server Authentication EKU, and RFC 2818 wildcards are supported. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Public trusted certificate for the SBC. Checked 2026-09-30.
[^9]: Microsoft certifies specific SBC firmware versions and supports higher firmware versions as long as the major.minor version is the same as a documented version. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Introductory note on certification before the Certified SBC vendors table. Checked 2026-09-30.
[^10]: Microsoft SIP endpoints currently accept SBC certificates without the Client Authentication EKU and say they will announce any change in advance. Source: [What's New Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new), Clarification on Client Authentication Extended Key Usage (EKU). Checked 2026-09-30.
[^11]: Direct Routing matches the FQDN in the Contact header against the certificate's CN or SAN (wildcards allowed) and then uses that FQDN, or its parent domain, to find the tenant; a mismatch fails the call. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Processing the incoming request: finding the tenant and user, steps 1-3; Use of FQDN name in Contact or Record-Route. Checked 2026-09-30.
[^12]: Every OPTIONS and INVITE the SBC sends to Direct Routing must carry the paired SBC FQDN in the Contact header; a Contact with an IP address is refused with 403 Forbidden. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Detailed requirements for Contact header and Request-URI > Contact header. Checked 2026-09-30.
[^13]: Microsoft lists Cisco Unified Border Element as certified for Direct Routing, both non-media bypass and media bypass, on 1000 Series ISR, 4000 Series ISR, CSR 1000V, ASR 1000 and Catalyst 8000 Edge platforms. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Cisco rows. Checked 2026-09-30.
[^14]: Because Microsoft accepts only four ECDHE-RSA suites and Cisco's CUBE example tls-cipher names are AES128_GCM_SHA256 and AES256_GCM_SHA384, the administrator must confirm from the TLS connection detail that the negotiated suite is one Microsoft accepts (inferred). Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), TLS cipher configuration example, read against ms-learn-dr-connect-sbc Considerations TLS bullet. Checked 2026-09-30.
[^15]: Because Cisco's command reference describes localhost dns as covering From, Call-ID and Remote-Party-ID but Microsoft requires the SBC FQDN specifically in Contact, an administrator should confirm the Contact header in a CUBE SIP trace and correct it with a SIP profile if it still carries an IP (inferred). Source: [Cisco IOS Voice Command Reference - K through R - L](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/vcr3/vcr3-cr-book/vcr-l1.html), localhost command entry, read against ms-learn-dr-protocols-sip Contact header section. Checked 2026-09-30.
[^16]: IOS XE SIP dial-peers can reference a voice class server-group (session server-group), a tenant (voice-class sip tenant), an OPTIONS keepalive profile, a voice class stun-usage, an e164-pattern-map destination, incoming URI matching and separate bind control and bind media interfaces. Source: [SIP Dial Peer Configurations - IOS-XE VoIP](https://developer.cisco.com/docs/ios-xe-voip/sip-dial-peer-configurations/), SIP Dial Peer Configurations: session server-group, voice-class sip tenant, options-keepalive profile, voice class stun-usage, destination e164-pattern-map, incoming uri, bind. Checked 2026-09-30.
[^17]: In Microsoft's certified SBC list the CUBE rows are marked 911 Service Provider capable but not ELIN capable, and Cisco does not appear in the Local Media Optimization support table. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table Cisco rows (ELIN capable column); Support for Local Media Optimization table. Checked 2026-09-30.
[^18]: CUBE ICE-Lite is configured with voice class stun-usage <tag> and 'stun usage ice lite', and Cisco lists IPv6, ANAT, codec transparent, SDP passthrough, media flow-around, MTP and TCL/VXML scripts as unsupported with it. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards: ICE-Lite Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-cube-icelite.html), Restrictions; Configuring ICE-Lite. Checked 2026-09-30.
[^19]: Cisco documents show voip ice summary, show voip ice instance call-id <id>, show voip ice global-stats and show voip rtp connections to verify ICE-Lite on CUBE. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards: ICE-Lite Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-cube-icelite.html), Verification section. Checked 2026-09-30.
[^20]: When OPTIONS keepalive fails for every destination of a dial-peer, CUBE marks that dial-peer inactive (busyout); status is shown by show voice class sip-options-keepalive <id>, show dial-peer voice summary and show dial-peer voip keepalive status <tag>. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Trunk Monitoring](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_oodo-ping-group.html), Feature description; verification section. Checked 2026-09-30.
[^21]: A CUBE voice class sip-options-keepalive profile sets up-interval (default 60 s), down-interval (default 30 s), retry (default 5), transport (including tcp tls) and sip-profiles, and is attached to a dial-peer with voice-class sip options-keepalive profile <id>. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Trunk Monitoring](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_oodo-ping-group.html), Configuring the keepalive profile; applying to dial peers. Checked 2026-09-30.
[^22]: Cisco's localhost dns:<host.domain> command substitutes a DNS name for the physical IP in the From, Call-ID and Remote-Party-ID headers of outgoing messages, and voice-class sip localhost overrides it per dial-peer. Source: [Cisco IOS Voice Command Reference - K through R - L](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/vcr3/vcr3-cr-book/vcr-l1.html), localhost command entry. Checked 2026-09-30.
[^23]: Microsoft lists CUBE as supported from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge) with 17.6.1a recommended (17.3.3 recommended for CSR 1000V). Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Cisco rows, Software version column. Checked 2026-09-30.
[^24]: CUBE SIP profiles (voice class sip-profiles) add, modify or remove SIP and SDP headers with request/response rules; they apply outbound via voice-class sip profiles on a dial-peer, while inbound profiles need 'sip-profiles inbound' enabled first; debug ccsip feature sip-profiles traces them. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Profiles](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-sip-param-mod.html), SIP profile configuration; inbound SIP profiles; verification and troubleshooting. Checked 2026-09-30.
[^25]: CUBE's voice class srtp-crypto lists preferred SRTP suites (AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32) and can be applied globally under voice service voip sip, in a voice class tenant, or per dial-peer with voice-class sip srtp-crypto, with 'srtp' enabling secure calls on the dial-peer. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), Voice class srtp-crypto configuration; application at global, tenant and dial-peer levels. Checked 2026-09-30.
[^26]: Cisco documents 'show sip-ua calls' as displaying the local and remote crypto keys of a CUBE call, which confirms SRTP was negotiated. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/cube_m_srtp-srtp-interworking.html), Verification section. Checked 2026-09-30.
[^27]: A CUBE voice class tenant acts as a per-trunk configuration template applied with voice-class sip tenant <tag>, and settings resolve in the order dial-peer, then tenant, then global. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Configure Multiple Trunks Using Tenants](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_voi-cube-multi-tenants.html), Overview; configuration precedence. Checked 2026-09-30.
[^28]: On CUBE, TLS 1.2 can be enforced globally with 'transport tcp tls v1.2' (minimum form) under sip-ua, ciphers are listed in voice class tls-cipher and bound with a trustpoint in voice class tls-profile, and a voice class tenant can apply the tls-profile with 'session transport tcp tls' and 'listen-port secure'. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), TLS cipher, TLS profile and SIP-UA/tenant configuration sections. Checked 2026-09-30.
[^29]: Cisco documents 'show sip-ua connections tcp tls brief' and 'show sip-ua connections tcp tls detail' to verify CUBE TLS connections. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), Verification section. Checked 2026-09-30.
[^30]: Cisco's CUBE SIP TLS chapter builds the CUBE identity by generating an RSA key pair and a crypto pki trustpoint with rsakeypair, fqdn, subject-name CN, subject-alt-name, enrollment terminal and revocation-check settings. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/m_sip_tls_support_cube.html), Certificate creation / trustpoint configuration section. Checked 2026-09-30.
[^31]: The dashboard's SIP options status is Active when OPTIONS flow regularly, 'Warning, no SIP options' when a configured SBC's OPTIONS were never seen, and 'Warning, SIP Messages aren't configured' when OPTIONS monitoring is off. Source: [Health dashboard for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-health-dashboard), The SBCs tab > SIP options status. Checked 2026-09-30.
[^32]: The Direct Routing health dashboard in the Teams admin center (Voice > Direct Routing) shows a per-SBC TLS connectivity status and warns when the SBC certificate expires within 30 days. Source: [Health dashboard for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-health-dashboard), View the health dashboard; The SBCs tab > TLS connectivity status. Checked 2026-09-30.
[^33]: The tenant must have a user in the SBC's domain with an assigned E3 or E5 license, and that domain's authentication type must be Managed; otherwise pairing fails with a 'domain was not configured for this tenant' error. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Connect the SBC to the tenant > Considerations, second and third bullets. Checked 2026-09-30.
[^34]: The SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant other than *.onmicrosoft.com, and a subdomain used in the FQDN must itself be registered. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use the Microsoft Teams admin center, item 3; Considerations list. Checked 2026-09-30.
[^35]: Configuring the global (org-wide default) online voice routing policy applies it to all voice-enabled users and can send Calling Plan and Operator Connect users' calls to the Direct Routing trunk; Microsoft advises a custom policy assigned to individual users instead. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Voice routing policy considerations, Caution item 1. Checked 2026-09-30.
[^36]: GCC High uses the single Direct Routing FQDN sip.pstnhub.gov.teams.microsoft.us (52.127.88.0/21) and DoD uses sip.pstnhub.dod.teams.microsoft.us (52.127.64.0/21), with no secondary or tertiary FQDNs. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling: GCC High; SIP signaling: DoD; Media processor IP ranges. Checked 2026-09-30.
[^37]: For GCC High and DoD clouds the SBC must be connected with PowerShell because the option is not available in the Teams admin center. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Note after the introduction. Checked 2026-09-30.
[^38]: The SBC must support ICE restarts because Direct Routing restarts ICE with new candidates when a bypassed call is transferred to a Skype for Business, Teams web or Teams VDI client. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), ICE Restart: Media bypass call transferred to an endpoint that doesn't support media bypass. Checked 2026-09-30.
[^39]: Media bypass is not supported when IPv6 is used for SIP, media or the Teams client; IPv6 Direct Routing is supported only without media bypass and with IPv6 for both signaling and media. Source: [What's New Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new), IPv6 with non media bypass is now supported for Teams Phone. Checked 2026-09-30.
[^40]: The media bypass planning page lists only 52.112.0.0/14 as the media processor and transport relay range for Microsoft 365, Office 365 and GCC (disputed). Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Requirements for using Transport Relays; Requirements for using media processors. Checked 2026-09-30.
[^41]: The Plan Direct Routing page tells administrators to allow media traffic for both 52.112.0.0/14 and 52.120.0.0/14 for Microsoft 365 and Office 365 (disputed). Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Media processor IP ranges > Microsoft 365 / Office 365. Checked 2026-09-30.
[^42]: The dashboard's network effectiveness ratio counts answered, busy, ring-no-answer and terminal-reject calls as delivered, and with fewer than 100 calls analysed a low ratio can still be normal. Source: [Health dashboard for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-health-dashboard), The SBCs tab > Network effectiveness. Checked 2026-09-30.
[^43]: Microsoft states that Direct Routing SIP endpoint certificates issued by a new CA were rolled out in production at the end of July 2026 and that the sip.g1.pstnhub.microsoft.com testing endpoint is discontinued. Source: [What's New Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new), Testing endpoint for upcoming certificate changes (February 16, 2026), Warning box. Checked 2026-09-30.
[^44]: An SBC is paired either in the Teams admin center under Voice > Direct Routing > SBCs > Add, or with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use the Microsoft Teams admin center; Use PowerShell > Connect the SBC to the tenant. Checked 2026-09-30.
[^45]: Direct Routing does not support Delayed Offer INVITEs (INVITE without SDP) and does not support SIPS URIs. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Non-media bypass flow note; note under Processing the incoming request. Checked 2026-09-30.
[^46]: Direct Routing does not support media re-targeting: if the SBC signals a new media IP mid-call, Direct Routing never sends media to the new address. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Final note on the page. Checked 2026-09-30.
[^47]: Mapping multiple IP addresses to the same FQDN on the SBC side is not supported for Direct Routing. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations list, bullet on multiple IPs. Checked 2026-09-30.
[^48]: SIP OPTIONS from the SBC must be sent no more often than once every 60 seconds and no less often than once every 180 seconds per trunk per endpoint. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations list, SIP OPTIONS pings bullet. Checked 2026-09-30.
[^49]: When Direct Routing sees incoming OPTIONS from an SBC it starts sending its own OPTIONS to the SBC FQDN given in the Contact header of those incoming OPTIONS. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Verify the SBC connection > Validate SIP options. Checked 2026-09-30.
[^50]: For incoming calls Direct Routing requires the phone numbers in the Request-URI and the From header to carry a leading plus sign, and Microsoft recommends always adding user=phone to the Request-URI. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Request-URI; From Header; Use of Request-URI parameter user=phone. Checked 2026-09-30.
[^51]: If the SBC advertises REFER in its Allow header, Direct Routing sends REFER to the SBC for transfers; this method is mandatory for media bypass certification, and transfer without SBC REFER handling is not supported in media bypass mode. Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Call transfer; SIP proxy send the Refer to the SBC and acts as a Transferor. Checked 2026-09-30.
[^52]: Microsoft's SIP protocol page both says Direct Routing rejects SIP requests that carry a Replaces header and says the SBC must support INVITE with Replaces (disputed). Source: [Teams Phone System Direct Routing: SIP protocol](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-sip), Note under Processing the incoming request (Replaces headers); Replaces option section. Checked 2026-09-30.
[^53]: The PowerShell sequence for routing is Set-CsOnlinePstnUsage to add a usage, New-CsOnlineVoiceRoute with -NumberPattern, -OnlinePstnGatewayList and -OnlinePstnUsages, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy, verified with Get-CsOnlineUser selecting OnlineVoiceRoutingPolicy. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Configuration steps > Using PowerShell, steps 1-4. Checked 2026-09-30.
[^54]: Direct Routing call routing uses voice routing policies that contain ordered PSTN usages, which contain voice routes pairing a number pattern with online PSTN gateways; usages are evaluated in order and the first match wins, and SBCs within one route are tried in random order. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Call routing overview; Example 1 note on random order; Example 2 note on PSTN usage order. Checked 2026-09-30.
[^55]: Online PSTN gateway defaults are SendSIPOptions True (turning it off excludes the SBC from monitoring and alerting), FailoverResponseCodes 408, 503 and 504, and FailoverTimeSeconds 10; Enabled can be set false to take the SBC out of service for maintenance. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table rows Enabled, Send SIP options, Failover response codes, Failover times. Checked 2026-09-30.
[^56]: SBCs must trust seven root CAs for the Microsoft Teams SIP interface: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root Certificate Authority 2017 and Microsoft RSA Root Certificate Authority 2017, for both client and server certificates. Source: [What's New Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new), Update on upcoming certificate changes (December 12, 2025) > Changes and call to action; Summary. Checked 2026-09-30.
[^57]: The commercial and GCC Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and Microsoft says to allow signaling to and from all these ranges rather than only the addresses DNS returns. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling: FQDNs, IP ranges and Important note. Checked 2026-09-30.
[^58]: SIP/TLS from the SBC goes to the Microsoft SIP proxy on port 5061, and SIP/TLS from the Microsoft SIP proxy (source ports 1024-65535) goes to the port configured on the SBC. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling ports table. Checked 2026-09-30.
[^59]: Microsoft's example Teams-to-SBC offer uses RTP/SAVP with a=crypto AES_CM_128_HMAC_SHA1_80, so the SBC leg toward Teams is SRTP with SDES keys (inferred). Source: [What's New Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new), AMR-WB is enabled for Direct Routing trunks on non bypass calls, SDP before/after example. Checked 2026-09-30.
[^60]: Direct Routing requires users to be in Teams Only mode (the UpgradeToTeams instance of TeamsUpgradePolicy) so that incoming calls land in the Teams client. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Assign Teams Only mode to users to ensure calls land in Microsoft Teams. Checked 2026-09-30.
[^61]: Microsoft forces TLS 1.2 on the Direct Routing SIP interface and requires the SBC to connect with one of four ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384 or AES128-SHA256. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations list, TLS1.2 bullet. Checked 2026-09-30.
[^62]: Microsoft's post-configuration checklist is to verify a healthy SBC connection, inbound and outbound PSTN calling, emergency calling if configured, failover between SIP connection points, voice routing policy assignment and call quality. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Verify your deployment. Checked 2026-09-30.
[^63]: To escalate an SBC-related Direct Routing issue to Microsoft, the customer must first contact the SBC vendor and present the vendor's investigation report with its ticket reference. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Note under 'Establish a joint support process with the SBC vendors'. Checked 2026-09-30.
[^64]: Microsoft's pairing check is that Get-CsOnlinePSTNGateway lists the SBC with Enabled True and that the SBC both receives 200 OK to its outgoing OPTIONS and answers Direct Routing's OPTIONS with 200 OK. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Verify the SBC connection > Check whether the SBC is on the list of paired SBCs; Validate SIP options. Checked 2026-09-30.
[^65]: Direct Routing lets an organization use any PSTN operator by connecting it through a certified SBC that is procured, installed and managed by the customer, an integrator or a Direct-Routing-as-a-Service provider. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options, bullet 'Direct Routing'. Checked 2026-09-24.
[^66]: Direct Routing requires a Microsoft-certified SBC, PSTN trunks to it, users homed online, a public IP, an SBC FQDN in a verified tenant domain (not *.onmicrosoft.com) with public DNS, and a publicly trusted TLS certificate. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, section 'Infrastructure requirements' table and section 'SBC domain names'. Checked 2026-09-24.
[^67]: Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used, expects the SBC vendor to investigate first and escalate, and may decline support requests involving non-certified SBCs. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, sections 'Supported Session Border Controllers (SBCs)' and 'Support boundaries'. Checked 2026-09-24.
[^68]: To use PSTN telephony with Teams Phone, a user account must be licensed with the Teams Phone application and also be equipped with a PSTN solution from a PSTN service provider. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options, section 'What is the Public Switched Telephone Network (PSTN)?'. Checked 2026-09-24.
[^69]: Direct Routing is not supported in Islands coexistence mode. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, section 'Licensing requirements', Note. Checked 2026-09-24.
[^70]: Direct Routing media between Microsoft media processors and the SBC uses UDP/SRTP ports 3478-3481 and 49152-53247 in both directions, and Microsoft recommends at least two media ports per concurrent call on the SBC. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, section 'Media ports' table and Tip. Checked 2026-09-24.
[^71]: For Microsoft 365, Office 365 and GCC, the SBC connects to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com in priority order over SIP/TLS to port 5061; GCC High uses sip.pstnhub.gov.teams.microsoft.us and DoD uses sip.pstnhub.dod.teams.microsoft.us. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, sections 'SIP signaling: FQDNs', 'SIP signaling: GCC High', 'SIP signaling: DoD', 'SIP signaling ports'. Checked 2026-09-24.
[^72]: Direct Routing supports SILK, G.711, G.722, G.729 and AMR-WB between Teams and the SBC, with AMR-WB supported only without media bypass. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, section 'Supported codecs'. Checked 2026-09-24.
[^73]: Direct Routing requires specific emergency call routing policies, whereas with the other PSTN options the carrier handles much of the emergency call routing configuration. Source: [Plan and manage emergency calling](https://learn.microsoft.com/en-us/microsoftteams/what-are-emergency-locations-addresses-and-call-routing), Plan and manage emergency calling, section 'Emergency call routing'. Checked 2026-09-24.
