# Enabling OAuth refresh-token login for Jabber and Webex App in Unified CM

Systems: Cisco Unified CM

For Unified CM administrators who also administer or coordinate with the owners of IM and Presence, Unity Connection and Expressway MRA for the same users.

Canonical: https://warmtransfer.net/guides/cucm-oauth-refresh-login-setup

Last verified: 2026-10-02

OAuth with Refresh Login Flow is a Unified CM enterprise parameter, set in Cisco Unified CM Administration at System > Enterprise Parameters in the SSO and OAuth Configuration section, and it defaults to Disabled[^37][^36]. When it is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change[^14].

## Before you start

- Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled[^34].
- The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work[^2].
- Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access-token and refresh-token expiry timers are Unified CM enterprise parameters[^55].
- OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later[^30].
- With OAuth Refresh Logins, the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days[^12].
- Each time an access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM[^46].
- Unified CM access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted[^53].
- For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default[^25].
- Cisco Jabber OAuth can be set up with or without SSO, and if SSO is used, Cisco says it must be enabled for all services[^35].
- SAML SSO itself is configured at System > SAML Single Sign On in Cisco Unified CM Administration, and the Cisco Tomcat service must be restarted both before and after SSO is enabled[^56].
- Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients[^13].

See also [Setting up SAML SSO for Unified CM](https://warmtransfer.net/knowledge/cucm-saml-sso-setup).

See also [Expressway and Mobile and Remote Access](https://warmtransfer.net/knowledge/cucm-expressway-mra).

See also [Cisco Unity Connection voicemail and migration](https://warmtransfer.net/knowledge/cucm-unity-connection).

## What changes by situation

- Where will you set the access-token and refresh-token lifetimes? Keep Cisco's defaults (60 minutes / 60 days); Set custom values in the Unified CM enterprise parameters; Set the refresh-token lifetime from Control Hub (Cloud-Connected UC).
- On Release 15 should Webex App refresh tokens renew automatically? Keep Auto Renew Refresh Token enabled (the default); Disable it so refresh tokens are not auto-extended.
- How is IM and Presence deployed for these users? IM and Presence nodes are in the same cluster as Unified CM; IM and Presence central cluster serving remote telephony clusters; No IM and Presence Service.
- Do Jabber or Webex App users get voicemail from Unity Connection? Yes from Unity Connection; No Unity Connection integration for these clients.
- Do clients sign in over Mobile and Remote Access through Expressway? Yes for some or all users; No and on-premises sign-in only.

## Step 1: Inventory versions and the current key state

### Do

Record the Unified CM release on every cluster, because Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later[^55]. Version 15 is the latest Unified CM major release listed on Cisco's support pages[^57], and Version 12.5 reached end of support on 31 August 2025[^58]. The end of software maintenance releases for Unified CM Version 14 was 7 April 2026[^59]. WarmTransfer's reading of the sources is that 15SU4a is the newest build with published ReadMe and release notes, so new deployments and upgrades would normally target 15SU4a or later[^60]. Note whether each cluster is at 12.5(1)SU7, 14SU3 or later, because from those releases subscriber nodes as well as the publisher can update the refresh token, and the change replicates across the cluster[^52]. Confirm that Jabber is Release 11.9 or later[^30]. In standard deployments, confirm that IM and Presence runs a version matching Unified CM, because a version mismatch is not supported[^61]. Where clients use Mobile and Remote Access, record the Expressway version: Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality[^32].

### Verify

Run `show key authz signing` and `show key authz encryption` on every Unified CM and IM and Presence node and compare the results, as Cisco TAC does to verify OAuth key consistency[^49]. Suggested check: record the outputs so later steps can compare against them.

## Step 2: Set the token lifetimes

**Keep Cisco's defaults (60 minutes / 60 days)**

### Do

Leave the access-token lifespan at its default of 60 minutes and the refresh-token life at its default of 60 days[^12].

### Verify

In System > Enterprise Parameters, OAuth Access Token Expiry Timer (minutes) shows its default of 60[^1][^55]. Suggested check: confirm that the refresh-token timer also still shows its default value.

**Set custom values in the Unified CM enterprise parameters**

### Do

In System > Enterprise Parameters, set OAuth Access Token Expiry Timer (minutes) to a value from 1 to 1440[^1][^55]. Set the refresh-token expiry timer, which is also a Unified CM enterprise parameter[^55]. We infer that a longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows[^26]. Click Save[^15].

### Verify

Suggested check: re-open the enterprise parameters page and confirm both timers show the values you saved.

### Rollback

Set the access-token timer back to 60 minutes and the refresh-token timer back to 60 days, the defaults[^12][^1].

**Set the refresh-token lifetime from Control Hub (Cloud-Connected UC)**

### Do

Confirm the prerequisites: Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later[^5]. In Control Hub, go to Services > Calling > Client Settings > Unified CM Settings and enter a value from 1 to 1825 days in Expiration timer for OAuth refresh token[^7]. Schedule the change, because it takes effect immediately and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate[^6].

### Verify

Check each cluster for a cluster-level value, because after the expiry is first set from Control Hub it can be changed at the individual cluster level, and the cluster-level setting always takes priority[^4].

### Rollback

Set Expiration timer for OAuth refresh token back to its default of 60 days[^7]. This change also takes effect immediately and invalidates previously issued refresh tokens[^6].

## Step 3: Decide on refresh-token auto-renewal (Release 15)

**Keep Auto Renew Refresh Token enabled (the default)**

### Do

Leave the Auto Renew Refresh Token enterprise parameter enabled, which is its default from Release 15[^3]. From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime[^54].

### Verify

Suggested check: confirm the parameter reads Enabled on the enterprise parameters page.

**Disable it so refresh tokens are not auto-extended**

### Do

Set Auto Renew Refresh Token to Disabled, after which Unified CM does not auto-extend refresh tokens[^3]. Click Save[^15].

### Verify

Suggested check: re-open the enterprise parameters page and confirm the parameter reads Disabled.

### Rollback

Set Auto Renew Refresh Token back to Enabled, its default[^3].

## Step 4: Enable OAuth with Refresh Login Flow on Unified CM

### Do

In Cisco Unified CM Administration, go to System > Enterprise Parameters, and in the SSO and OAuth Configuration section set OAuth with Refresh Login Flow to Enabled[^37]. In an IM and Presence centralized deployment, set it on each telephony cluster, which automatically enables the feature in the IM and Presence central cluster[^21]. Click Save; Cisco's generic enterprise-parameter procedure follows Save with Reset and OK to reset all devices[^15]. The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved[^47].

### Verify

Suggested check: re-open the enterprise parameters page and confirm the parameter reads Enabled. Jabber detects the change at its configuration re-fetch interval[^31].

### Rollback

Set OAuth with Refresh Login Flow back to Disabled, its default[^37][^36]. Disabling the feature after it has been enabled requires resetting all Cisco Jabber clients[^13], and Jabber clears cached credentials and has the user sign out and sign in again[^31].

## Step 5: Bring IM and Presence in line

**IM and Presence nodes are in the same cluster as Unified CM**

### Do

The Unified CM publisher replicates the OAuth keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes[^43].

### Verify

Run `show key authz signing` and `show key authz encryption` on the IM and Presence nodes and compare the results with the Unified CM nodes[^49].

**IM and Presence central cluster serving remote telephony clusters**

### Do

Confirm that every remote telephony cluster runs at least 11.5(1)SU4, the minimum for OAuth Refresh Logins in an IM and Presence centralized deployment[^22]. The setting made on the telephony clusters automatically enables the feature in the IM and Presence central cluster[^21].

### Verify

On the central cluster, each remote telephony cluster that supports the feature shows Synchronized for OAuth Refresh Logins, and earlier clusters may show Unsynchronized[^23].

### Rollback

Suggested rollback: disable the parameter on each telephony cluster as described in the Step 4 rollback.

**No IM and Presence Service**

### Do

Run `show key authz signing` and `show key authz encryption` on every Unified CM node and compare the results[^49].

### Verify

Suggested check: confirm the outputs are identical on every node.

## Step 6: Enable refresh login on Unity Connection

**Yes from Unity Connection**

### Do

In Cisco Unity Connection Administration, go to System Settings > Enterprise Parameters > SSO and OAuth Configuration and set OAuth with Refresh Login Flow to Enabled, because OAuth flow is disabled by default on Unity Connection[^11]. Go to System Settings > Authz Server > Add New and add the Unified CM publisher of the associated phone system; with Session Management Edition, each leaf-cluster publisher can be added[^9]. Enter a username and password that are the same as the Unified CM system administrator credentials[^8]. The Ignore Certificate Errors check box is an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store[^10].

### Verify

Suggested check: confirm the server entry saves without a certificate or credential error. Suggested check: after Step 9, confirm that a pilot user's visual voicemail works.

### Rollback

Suggested rollback: delete the server entry you added. Set OAuth with Refresh Login Flow on Unity Connection back to Disabled, its default[^11].

**No Unity Connection integration for these clients**

### Do

Expressway's OAuth token with refresh option requires OAuth with refresh on Unity Connection only where Unity Connection is used[^17].

### Verify

Suggested check: confirm that the clients in scope are not configured with any voicemail server that would need this change.

## Step 7: Authorize MRA by OAuth token with refresh

**Yes for some or all users**

### Do

On Unified CM, tick Enable Mobile and Remote Access in the User Profile (User Management > User Settings > User Profile) used by each Jabber user, because it is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA[^33]. On Expressway-C, go to Configuration > Unified Communications > Configuration > MRA Access Control and set Authorize by OAuth token with refresh to On; Cisco recommends it for all deployments that can support it, and its default is On[^19]. This option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection[^17]. Refresh the Unified CM nodes defined on the Expressway, which fetches the keys the Expressway needs to decrypt the tokens[^20]. We infer that enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys[^27]. Leave Check for internal authentication availability at its default of No, because Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients[^16]. The separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths[^18].

### Verify

Suggested check: in Step 9, confirm that an off-network client signs in remotely and stays signed in past the access-token lifetime.

### Rollback

Set Authorize by OAuth token with refresh to Off on Expressway-C[^19]. Suggested rollback: then reverse Step 4 if the whole change is being backed out.

**No and on-premises sign-in only**

### Do

The Enable Mobile and Remote Access check box in the User Profile is mandatory only for Cisco Jabber users who use OAuth Refresh Logins over MRA[^33].

### Verify

Suggested check: confirm that the clients in scope sign in only from inside the network.

## Step 8: Get clients onto the new flow

### Do

Tell users to expect one sign-out and sign-in, because when OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again[^31]. Reset all Cisco Jabber and Webex clients, as the 12.5(1) Configure Refresh Logins procedure directs[^47].

### Verify

Suggested check: confirm each pilot user signs in once and is not prompted again afterwards. Where SSO is used, Cisco says it must be enabled for all services[^35].

## Step 9: Test

### Do

With a pilot user, sign in and leave the client running past the access-token lifetime, since the client requests a new access token each time the current one reaches 75 percent of its lifespan[^46]. Change networks and confirm no sign-in prompt appears, which is the Fast Login behaviour the enabled parameter provides[^14].

### Verify

A Jabber log line reading `Failed to get valid access token from refresh token, maybe server issue` indicates that a refresh-token exchange failed[^29]. If failures appear, check the Unified CM Tomcat ssosp log4j directory, where SSO application logs are in ssoApp.log and certificate operations are in certMgmt logs[^51], and re-run the `show key authz signing` and `show key authz encryption` comparison[^49]. Suggested check: repeat the test from outside the network for users who sign in remotely.

## Step 10: Put a leaver-revocation procedure in place

### Do

Add a call to `https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>`, made with administrator credentials, to the leaver process; it revokes the user's current refresh token[^48].

### Verify

After revocation, the user cannot obtain new access tokens[^48]. Suggested check: revoke a test user's token and confirm the client is prompted to sign in once its current access token expires.

### Rollback

Suggested rollback: have the test user sign in again to obtain a new refresh token.

## Step 11: Regenerate OAuth keys only if they are compromised

### Do

Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised[^41]. Cisco recommends regenerating during off-hours, because current access and refresh tokens that use those keys become invalid[^42]. Regenerate the encryption key from the CLI with `set key regen authz encryption`, confirmed by yes, since it can be regenerated only from the CLI[^40]. Regenerate the signing key with `set key regen authz signing`, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate[^44]. The publisher replicates the new keys to all Unified CM cluster nodes, including any local IM and Presence Service nodes[^43]. Where Expressway is used, refresh the Unified CM nodes defined on it so it fetches the keys it needs to decrypt the tokens[^20]. Restart the Cisco XCP Authentication Service on all IM and Presence nodes so that Jabber OAuth login works[^24].

### Verify

Run `show key authz signing` and `show key authz encryption` on every Unified CM and IM and Presence node and compare the results[^49]. Expect every user to sign in again, because existing access and refresh tokens that used the old keys are invalid[^42].

## Applicability

Applies to: Cisco Unified Communications Manager, Cisco Jabber, Cisco Webex Control Hub, Cisco Unity Connection, Cisco Expressway, and Cisco Unified CM IM. Deployments: on-premises and hybrid. Sources checked 2026-10-02. Auto Renew Refresh Token is a Release 15 addition[^3]. Subscriber-node refresh-token updates apply from Unified CM 12.5(1)SU7 and 14SU3 onwards[^52]. The Control Hub refresh-token timer requires Cloud-Connected UC with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later[^5].

## What remains uncertain

- The allowed range for the Unified CM refresh-token expiry timer enterprise parameter, and how it differs by release, is not covered by the sources below.
- The minimum Expressway version for given Jabber and Webex App releases is not covered by the sources below.
- Whether changing the Unified CM refresh-token expiry enterprise parameter invalidates already-issued refresh tokens is not covered by the sources below.
- Whether a full device reset, rather than only a client reset, is required after saving this parameter is not covered by the sources below.
- The exact steps to bring a centralized IM and Presence cluster and Unity Connection in line after OAuth key regeneration are not covered by the sources below.

## Sources

[^1]: The OAuth Access Token Expiry Timer (minutes) enterprise parameter accepts 1 to 1440 minutes and defaults to 60. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), Configure Refresh Logins / OAuth parameter table, OAuth Access Token Expiry Timer (minutes). Checked 2026-10-02.
[^2]: The Jabber planning guide states that OAuth refresh tokens must be turned on across all deployed components (Unified CM, IM and Presence, Unity Connection, Expressway) for the feature to work. Source: [Planning Guide for Cisco Jabber 14.1 - User Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/jabber/14_1/cjab_b_planning-guide-for-jabber141/cjab_m_planning-user-management-129.html), User Management > OAuth. Checked 2026-10-02.
[^3]: Release 15 adds the Auto Renew Refresh Token enterprise parameter, enabled by default; when it is disabled Unified CM does not auto-extend refresh tokens. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > Auto Renew Refresh Token. Checked 2026-10-02.
[^4]: After the refresh-token expiry is first set from Control Hub it can be changed again at the individual cluster level, and the cluster-level setting always takes priority. Source: [Auto-Provisioning of Webex App for Calling in Webex (Unified CM)](https://help.webex.com/en-US/article/ki34wo/Auto-Provisioning-of-Webex-App-for-Calling-in-Webex-(Unified-CM)), Set Expiration Timer for OAuth Refresh Token. Checked 2026-10-02.
[^5]: The Control Hub article's prerequisites are Cloud-Connected UC activated with on-premises devices communicating with Control Hub, Unified CM clusters at 11.5 or above, and Webex App 41.12 or later. Source: [Auto-Provisioning of Webex App for Calling in Webex (Unified CM)](https://help.webex.com/en-US/article/ki34wo/Auto-Provisioning-of-Webex-App-for-Calling-in-Webex-(Unified-CM)), Prerequisite. Checked 2026-10-02.
[^6]: Changing the Control Hub refresh-token expiry takes effect immediately, and previously issued refresh tokens cease to be valid, forcing client applications that hold them to re-authenticate. Source: [Auto-Provisioning of Webex App for Calling in Webex (Unified CM)](https://help.webex.com/en-US/article/ki34wo/Auto-Provisioning-of-Webex-App-for-Calling-in-Webex-(Unified-CM)), Set Expiration Timer for OAuth Refresh Token. Checked 2026-10-02.
[^7]: In Control Hub, Services > Calling > Client Settings > Unified CM Settings has an Expiration timer for OAuth refresh token field accepting 1 to 1825 days, default 60. Source: [Auto-Provisioning of Webex App for Calling in Webex (Unified CM)](https://help.webex.com/en-US/article/ki34wo/Auto-Provisioning-of-Webex-App-for-Calling-in-Webex-(Unified-CM)), Set Expiration Timer for OAuth Refresh Token. Checked 2026-10-02.
[^8]: The username and password entered for a Unity Connection Authz server must be the same as the Unified CM system administrator credentials. Source: [System Administration Guide for Cisco Unity Connection Release 15 - System Settings](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/15/administration/guide/b_15cucsag/b_15cucsag_chapter_010000.html), System Settings > Authz Server. Checked 2026-10-02.
[^9]: Unity Connection uses the Unified CM publisher of the associated phone system as its Authz server, configured at System Settings > Authz Server > Add New; with Session Management Edition each leaf-cluster publisher can be added. Source: [System Administration Guide for Cisco Unity Connection Release 15 - System Settings](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/15/administration/guide/b_15cucsag/b_15cucsag_chapter_010000.html), System Settings > Authz Server. Checked 2026-10-02.
[^10]: The Unity Connection Authz server page has an Ignore Certificate Errors check box as an alternative to uploading valid Unified CM certificates to the Unity Connection Tomcat trust store. Source: [System Administration Guide for Cisco Unity Connection Release 15 - System Settings](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/15/administration/guide/b_15cucsag/b_15cucsag_chapter_010000.html), System Settings > Authz Server, Ignore Certificate Errors field. Checked 2026-10-02.
[^11]: OAuth flow is disabled by default on Unity Connection and is enabled in Cisco Unity Connection Administration at System Settings > Enterprise Parameters > SSO and OAuth Configuration by setting OAuth with Refresh Login Flow to Enabled. Source: [System Administration Guide for Cisco Unity Connection Release 15 - System Settings](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/connection/15/administration/guide/b_15cucsag/b_15cucsag_chapter_010000.html), System Settings > Authz Server, prerequisites. Checked 2026-10-02.
[^12]: With OAuth Refresh Logins the default access-token lifespan is 60 minutes and the default refresh-token life is 60 days. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework. Checked 2026-10-02.
[^13]: Cisco warns that once OAuth Refresh Logins are enabled, disabling the feature requires resetting all Cisco Jabber clients. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), Configure Refresh Logins, Note under OAuth with Refresh Login Flow. Checked 2026-10-02.
[^14]: When OAuth with Refresh Login Flow is Enabled, clients such as Cisco Jabber can use an OAuth-based Fast Login flow that does not require the user to sign in again, for example after a network change. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet. Checked 2026-10-02.
[^15]: Cisco's generic enterprise-parameter procedure is to edit the value, click Save, then click Reset and OK to reset all devices. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Configure Enterprise Parameters procedure. Checked 2026-10-02.
[^16]: Expressway's Check for internal authentication availability setting defaults to No, and Cisco warns that Yes can allow rogue inbound requests from unauthenticated remote clients. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Check for internal authentication availability. Checked 2026-10-02.
[^17]: Expressway's OAuth token with refresh option requires OAuth with refresh to be enabled on the Unified CM clusters and, where it is used, on Unity Connection. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh, requirements. Checked 2026-10-02.
[^18]: Expressway's separate Authorize by OAuth token option (previously SSO mode) requires authentication through the IdP, defaults to Off, and is available only with SAML SSO authentication paths. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Authorize by OAuth token (previously SSO mode). Checked 2026-10-02.
[^19]: On Expressway-C, Authorize by OAuth token with refresh is set under Configuration > Unified Communications > Configuration > MRA Access Control; Cisco recommends it for all deployments that can support it and its default is On. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh. Checked 2026-10-02.
[^20]: After enabling OAuth token with refresh, the Unified CM nodes defined on the Expressway must be refreshed, which fetches the keys the Expressway needs to decrypt the tokens. Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh. Checked 2026-10-02.
[^21]: In an IM and Presence centralized deployment, OAuth with Refresh Login Flow is set on the telephony cluster, and that setting automatically enables the feature in the IM and Presence central cluster. Source: [Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/im_presence/configAdminGuide/15_0/cup0_b_config-and-admin-guide-15/cup0_b_config-and-admin-guide-1401_chapter_01000.html), Configure Centralized Deployment > Configure OAuth Refresh Logins. Checked 2026-10-02.
[^22]: In an IM and Presence centralized deployment, the remote Unified CM telephony cluster must run at least 11.5(1)SU4 to support OAuth Refresh Logins. Source: [Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/im_presence/configAdminGuide/15_0/cup0_b_config-and-admin-guide-15/cup0_b_config-and-admin-guide-1401_chapter_01000.html), Configure Centralized Deployment > Configure OAuth Refresh Logins. Checked 2026-10-02.
[^23]: In an IM and Presence centralized deployment, a remote Unified CM telephony cluster's status shows Synchronized for OAuth Refresh Logins when it supports the feature, and earlier clusters may show Unsynchronized. Source: [Configuration and Administration of the IM and Presence Service, Release 15 and SUs - Configure Centralized Deployment](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/im_presence/configAdminGuide/15_0/cup0_b_config-and-admin-guide-15/cup0_b_config-and-admin-guide-1401_chapter_01000.html), Configure Centralized Deployment > remote telephony cluster status. Checked 2026-10-02.
[^24]: When OAuth keys are regenerated, the Cisco XCP Authentication Service must be restarted on all IM and Presence nodes for Jabber OAuth login to work. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework, Note on key regeneration. Checked 2026-10-02.
[^25]: For backward compatibility, older Jabber clients and supporting applications such as Cisco Unified RTMT can still authenticate with the implicit grant flow, which is enabled by default. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), OAuth Refresh Logins overview. Checked 2026-10-02.
[^26]: A longer refresh-token lifetime means fewer sign-in prompts but a longer window in which a lost device keeps access, so revoking a leaver's refresh token with the revoke API matters more as the lifetime grows (inferred). Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework, token lifetimes and revoke API. Checked 2026-10-02.
[^27]: Because Expressway fetches the Unified CM token keys only when its Unified CM nodes are refreshed and requires OAuth with refresh on Unified CM, enabling the Unified CM parameter before refreshing Expressway avoids MRA clients being validated against missing keys (inferred). Source: [Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - MRA Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X15-0/mra/exwy_b_mra-deployment-guide-x150/exwy_m_basic-configuration.html), MRA Configuration > MRA Access Control > Authorize by OAuth token with refresh. Checked 2026-10-02.
[^28]: Because Cisco documents different upper bounds for the refresh-token expiry (90 days for 12.0, 365 days for 12.5(1), 1825 days in Control Hub) and the Release 15 parameter text read here does not state one, the allowed range on a given cluster should be read from that cluster's own parameter help before choosing a value (inferred). Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), OAuth parameter table, compared with cisco-technote-212794-oauth-code-grant and webex-help-ki34wo-auto-provisioning-ucm. Checked 2026-10-02.
[^29]: A Jabber log line reading Failed to get valid access token from refresh token, maybe server issue indicates that a refresh-token exchange failed. Source: [Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0](https://www.cisco.com/c/en/us/support/docs/unified-communications/jabber/212794-cisco-collaboration-solutions-12-0-oaut.html), Troubleshoot > Jabber logs. Checked 2026-10-02.
[^30]: OAuth Refresh Logins for Cisco Jabber require Jabber Release 11.9 or later. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), OAuth Refresh Logins prerequisites. Checked 2026-10-02.
[^31]: When OAuth is enabled or disabled on any of the servers, Jabber detects it at its configuration re-fetch interval, clears cached credentials and has the user sign out and sign in again. Source: [Planning Guide for Cisco Jabber 14.1 - User Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/jabber/14_1/cjab_b_planning-guide-for-jabber141/cjab_m_planning-user-management-129.html), User Management > OAuth. Checked 2026-10-02.
[^32]: For Mobile and Remote Access deployments with Cisco Jabber, Cisco recommends enabling OAuth with Refresh Login Flow only with an Expressway version that supports it, warning that an incompatible version may impact Jabber functionality. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Note. Checked 2026-10-02.
[^33]: The Enable Mobile and Remote Access check box in the Unified CM User Profile (User Management > User Settings > User Profile) is mandatory for Cisco Jabber users who use OAuth Refresh Logins over MRA; non-Jabber users do not need it. Source: [Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Mobile and Remote Access](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/cucm_b_feature-configuration-guide-for-15/cucm_m_configure-mobile-and-remote-access.html), Configure Mobile and Remote Access Access Policy for Cisco Jabber Users, step 7 note. Checked 2026-10-02.
[^34]: Cisco states that enabling OAuth with Refresh Login Flow requires support from other Unified Communications components such as Expressway and Unity Connection, running compatible versions with the refresh login flow enabled. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Enabled bullet. Checked 2026-10-02.
[^35]: Cisco Jabber OAuth can be set up with or without SSO; if SSO is used, Cisco says it must be enabled for all services. Source: [Planning Guide for Cisco Jabber 14.1 - User Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/jabber/14_1/cjab_b_planning-guide-for-jabber141/cjab_m_planning-user-management-129.html), User Management > OAuth. Checked 2026-10-02.
[^36]: The OAuth with Refresh Login Flow enterprise parameter defaults to Disabled. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow. Checked 2026-10-02.
[^37]: The OAuth with Refresh Login Flow enterprise parameter is set in Cisco Unified CM Administration at System > Enterprise Parameters, in the SSO and OAuth Configuration section. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow. Checked 2026-10-02.
[^38]: The 12.0 TAC tech note gives the refresh-token expiry range as 1 to 90 days with a default of 60 days. Source: [Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0](https://www.cisco.com/c/en/us/support/docs/unified-communications/jabber/212794-cisco-collaboration-solutions-12-0-oaut.html), Configure > OAuth token expiry parameters. Checked 2026-10-02.
[^39]: In the Release 12.5(1) documentation, the OAuth Refresh Token Expiry Timer (days) enterprise parameter accepts 1 to 365 days and defaults to 60; after it expires the refresh token is invalid and the client must re-authenticate. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), Configure Refresh Logins / OAuth parameter table, OAuth Refresh Token Expiry Timer (days). Checked 2026-10-02.
[^40]: The OAuth encryption key can be regenerated only from the CLI, with set key regen authz encryption confirmed by yes. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_01111.html), Regenerate Keys for OAuth Refresh Logins. Checked 2026-10-02.
[^41]: Cisco TAC states the OAuth signing and encryption keys should be regenerated only if the administrator believes they have been compromised. Source: [Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0](https://www.cisco.com/c/en/us/support/docs/unified-communications/jabber/212794-cisco-collaboration-solutions-12-0-oaut.html), Troubleshoot > key mismatch, Note. Checked 2026-10-02.
[^42]: After the OAuth keys are regenerated, current access and refresh tokens that use those keys become invalid, and Cisco recommends doing it during off-hours. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_01111.html), Regenerate Keys for OAuth Refresh Logins. Checked 2026-10-02.
[^43]: The Unified CM publisher regenerates the OAuth keys and replicates them to all Unified CM cluster nodes, including any local IM and Presence Service nodes. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_01111.html), Regenerate Keys for OAuth Refresh Logins. Checked 2026-10-02.
[^44]: The OAuth signing key can be regenerated with the CLI command set key regen authz signing, or in Cisco Unified OS Administration at Security > Certificate Management by selecting the AUTHZ certificate and clicking Regenerate. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_01111.html), Regenerate Keys for OAuth Refresh Logins. Checked 2026-10-02.
[^45]: After regenerating OAuth keys, the new keys must also be regenerated and synced on an IM and Presence central cluster and on Cisco Expressway or Cisco Unity Connection. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Certificates](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_01111.html), Regenerate Keys for OAuth Refresh Logins, list of UC clusters. Checked 2026-10-02.
[^46]: Each time an OAuth access token reaches 75 percent of its lifespan, the client application requests a new access token from Unified CM. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework. Checked 2026-10-02.
[^47]: The 12.5(1) Configure Refresh Logins procedure ends by resetting all Cisco Jabber and Webex clients after the enterprise parameters are saved. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), Configure Refresh Logins, final step. Checked 2026-10-02.
[^48]: Unified CM exposes a REST endpoint, https://<UCMaddress>:8443/ssosp/token/revoke?user_id=<end_user>, called with administrator credentials, that revokes a user's current refresh token so the user cannot obtain new access tokens. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework > revoke refresh tokens. Checked 2026-10-02.
[^49]: Cisco TAC verifies OAuth key consistency by running show key authz signing and show key authz encryption on every Unified CM and IM and Presence node and comparing the results. Source: [Deploy And Troubleshoot Authorization Code Grant Flow - OAuth Enhancement: Cisco Collaboration Solutions 12.0](https://www.cisco.com/c/en/us/support/docs/unified-communications/jabber/212794-cisco-collaboration-solutions-12-0-oaut.html), Verify / Troubleshoot > key mismatch. Checked 2026-10-02.
[^50]: SIP OAuth Mode, supported for Cisco Jabber from Unified CM 12.5 onwards, includes setting OAuth with Refresh Login Flow to Enabled as part of its configuration. Source: [Feature Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - SIP OAuth Mode](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/cucm_b_feature-configuration-guide-for-15/cucm_m_sip-oauth-mode-on-unified.html), SIP OAuth Mode > Configure Refresh Logins. Checked 2026-10-02.
[^51]: OAuth and SSO operations on Unified CM are logged under the Tomcat ssosp log4j directory, with SSO application logs in ssoApp.log and certificate operations in certMgmt logs. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), OAuth troubleshooting log locations. Checked 2026-10-02.
[^52]: From Unified CM 12.5(1)SU7 and 14SU3 onwards, subscriber nodes as well as the publisher can update the refresh token in the requesting node's database, and the change replicates across the cluster. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Configure Enterprise Parameters and Services](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_m_configure-enterprise-parameters-and-services.html), Common Enterprise Parameters > SSO and OAuth Configuration > OAuth with Refresh Login Flow, Important. Checked 2026-10-02.
[^53]: Unified CM OAuth access tokens are encrypted, signed and self-contained JWTs (RFC 7519), while refresh tokens are signed but not encrypted. Source: [System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1) - Configure Cisco Jabber](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/12_5_1/systemConfig/cucm_b_system-configuration-guide-1251/cucm_b_system-configuration-guide-1251_chapter_0111000.html), OAuth Refresh Logins overview. Checked 2026-10-02.
[^54]: From Release 15, for Webex clients only, Unified CM renews the refresh token automatically when renewal is enabled on Unified CM and the Webex client and the refresh token has reached 50 percent of its lifetime. Source: [Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Identity Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/15_0/cucm_b_security-guide-release-15/cucm_m_identity-management.html), Identity Management > OAuth Framework, refresh token renewal paragraph. Checked 2026-10-02.
[^55]: Jabber OAuth with refresh tokens requires Unified CM 11.5(SU3) or 12.0 and later, and the access and refresh token expiry timers are Unified CM enterprise parameters. Source: [Planning Guide for Cisco Jabber 14.0 - User Management](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/jabber/14_0/cjab_b_planning-guide-cisco-jabber-14_0/cjab_b_planning-guide-cisco-jabber-129_chapter_011.html), User Management > OAuth. Checked 2026-09-25.
[^56]: SAML SSO is configured at System > SAML Single Sign On in Cisco Unified CM Administration, and the Cisco Tomcat service must be restarted both before and after SSO is enabled. Source: [SAML SSO Deployment Guide for Cisco Unified Communications Applications, Release 15 and SUs - SAML SSO Configuration](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/SAML_SSO_deployment_guide/15/cucm_b_saml-sso-deployment-guide-release-15/cucm_m_saml-sso-configuration-1251.html), Enable SAML SSO procedure. Checked 2026-09-30.
[^57]: Version 15 is the latest Cisco Unified Communications Manager major release listed on Cisco's support pages; it was released on 16 October 2023 and its status is Available. Source: [Cisco Unified Communications Manager (CallManager) - Support](https://www.cisco.com/c/en/us/support/unified-communications/unified-communications-manager-callmanager/series.html), Product status and Latest release fields; Supported versions list. Checked 2026-09-30.
[^58]: Cisco Unified CM Version 12.5 reached end of support on 31 August 2025. Source: [Cisco Unified Communications Manager (CallManager) - Support](https://www.cisco.com/c/en/us/support/unified-communications/unified-communications-manager-callmanager/series.html), Supported versions list, Version 12.5 entry (End-of-Support Date). Checked 2026-09-30.
[^59]: The end of software maintenance releases for Unified CM Version 14 was 7 April 2026. Source: [End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual](https://www.cisco.com/c/en/us/products/collateral/unified-communications/unified-communications-manager-callmanager/v-14-premises-calling-applications-eol.html), Table 1 End-of-life milestones, row End of SW Maintenance Releases Date. Checked 2026-09-30.
[^60]: As of 2026-09-30, the newest Unified CM build with published ReadMe and release notes is 15SU4a, and Version 14 has passed its end of software maintenance, so new deployments and upgrades would normally target 15SU4a or later (inferred). Source: [ReadMe for Cisco Unified Communications Manager Release 15SU4a](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/sustaining/cucm_b_readme-15su4a.html), Document header (Last Updated July 29 2026); combined with cisco-eol-v14-onprem-calling-apps Table 1. Checked 2026-09-30.
[^61]: In standard deployments, Unified CM and the IM and Presence Service must run supported, matching versions; a version mismatch is not supported. Source: [Installation Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Planning the Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/install/15/cucm_b_install-guide-cucm-imp-15/cucm_m_planning-the-installation.html), Version compatibility section. Checked 2026-09-30.
