Building a hybrid Unified CM and Teams Phone environment for a phased migration
Cisco Unified CM to Microsoft Teams Phone (Direct Routing)
Verified 2026-09-24 · 80 sources · tier 1–2
For Voice engineers administering a Cisco Unified Communications Manager cluster and a Microsoft 365 tenant during a phased migration to Teams Phone Direct Routing..
Microsoft Teams Phone delivers call control and PBX capabilities hosted in the Microsoft 365 cloud 64. Direct Routing enables connection of customer-provided Session Border Controllers (SBCs) and carrier trunks to integrate Teams Phone with on-premises platforms such as Cisco Unified Communications Manager during phased migrations 6536.
Before you start
- Confirm that each user scheduled for migration holds a Teams Phone application license and has an assigned PSTN connectivity solution 66. Stand-alone Microsoft Teams Phone Standard licenses require prerequisite licensing such as Microsoft 365 Business Basic, whereas Microsoft 365 E5 includes Teams Phone directly 6768.
- Verify that your tenant has registered and verified a domain name other than
*.onmicrosoft.comfor the SBC FQDN, and that a user on that domain holds an E3 or E5 license 42. - Verify that users to be migrated are homed online in the cloud, as Direct Routing requires users to be homed online and placed in Teams Only coexistence mode 69423. Direct Routing does not support Islands coexistence mode 70.
- Confirm the deployment of a certified SBC model and firmware release, as Microsoft supports Direct Routing only with certified SBCs 71. For Cisco Unified Border Element (CUBE), certification covers ISR 1000, ISR 4000, CSR 1000V, ASR 1000, and Catalyst 8000 Edge platforms starting from Cisco IOS XE 17.2.1r (17.3.2 for Catalyst 8000), with 17.6.1a recommended 2.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Two questions. One permanent page you can send to your manager.
Step 1 Confirm licensing, tenant, and user prerequisites
Do
Confirm that every user in the migration wave has a Teams Phone license and an underlying prerequisite subscription 6668. Confirm that the tenant contains a verified domain matching the SBC fully qualified domain name (FQDN) and has an active E3 or E5 license assigned on that domain 42. Ensure target user accounts are homed online in the cloud 694.
Verify
Confirm that the SBC domain appears as verified in the tenant and that target users hold a Teams Phone license 4266.
Rollback
Suggested rollback: No configuration changes are made in this step; adjust license assignments or tenant domain registrations as needed.
Step 2 Prepare the SBC that will face Teams
One shared SBC connects both Unified CM and Teams Phone to the PSTN
Do
Confirm that the existing SBC model and firmware version appear on Microsoft's certified list, noting that certification applies to specific firmware versions and newer builds are supported only within the same major.minor release 713. Configure the SBC with a public IP address and an FQDN ending in a registered tenant domain, mapping only one IP address to that SBC FQDN 694243. Install a public TLS certificate signed by a Certification Authority in the Microsoft Trusted Root Program, carrying the SBC FQDN in its Subject Common Name or Subject Alternative Name and including the Server Authentication EKU 6933. Configure TLS 1.2 using one of the four supported ECDHE-RSA AES-GCM or AES-CBC cipher suites toward Microsoft 46. Open firewall access for SIP/TLS signaling on port 5061 to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com, and sip3.pstnhub.microsoft.com across all commercial Microsoft Teams IP ranges (52.112.0.0/14 and 52.120.0.0/14), and open UDP/SRTP media ports 3478–3481 and 49152–53247 bidirectionally 723473.
Verify
Check that the SBC platform and firmware version match the certified list 23. Verify with public DNS lookups that mapping multiple IP addresses to the SBC FQDN is not configured 43.
Rollback
Suggested rollback: Remove the Teams-specific public DNS record, public certificate, and firewall openings while preserving existing Unified CM PSTN trunk configurations on the SBC.
A separate SBC is dedicated to Teams Direct Routing
Do
Deploy a dedicated certified SBC, such as a certified Cisco CUBE platform on a supported release (IOS XE 17.2.1r or later) 7123. Connect PSTN carrier trunks to this new SBC 6569. Assign the SBC a public IP address and an FQDN in a verified tenant domain, mapping only one IP address to the FQDN 694243. Install a public TLS certificate from a Microsoft Trusted Root Program member with the SBC FQDN in CN or SAN and Server Authentication EKU 6933. Configure TLS 1.2 with a supported ECDHE-RSA cipher suite 46. Open firewall signaling on port 5061 to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com, and sip3.pstnhub.microsoft.com covering Microsoft subnets 52.112.0.0/14 and 52.120.0.0/14, and open media ports 3478–3481 and 49152–53247 bidirectionally 723473.
Verify
Verify that the SBC model and major.minor firmware match Microsoft's certification records 713. Verify that mapping multiple IP addresses to the SBC FQDN is not configured 43. Suggested check: inspect the SBC management interface to verify that carrier PSTN trunks are online.
Rollback
Suggested rollback: Disconnect the dedicated SBC and remove its DNS and firewall configurations, leaving existing Unified CM gateway environments unaltered.
Step 3 Pair the SBC with the Teams tenant
Do
In PowerShell or under Voice > Direct Routing > SBCs in the Teams admin center, run New-CsOnlinePSTNGateway specifying the SBC FQDN, SIP signaling port, and -Enabled $true 44. Keep SendSIPOptions enabled so the SBC participates in Direct Routing monitoring and alert generation 45. Set -MaxConcurrentSessions to establish an alerting threshold that triggers notifications at 90 percent of capacity 38. Set -ForwardCallHistory $true if downstream systems or Unified CM require History-Info and Referred-By headers on forwarded calls 41. If evaluating media bypass, configure it per SBC using Set-CsOnlinePSTNGateway -MediaBypass, noting that SIP signaling continues to route through Microsoft cloud servers, or create a second FQDN pointing to the same SBC with a dedicated voice routing policy to trial bypass 2928.
Verify
Run Get-CsOnlinePSTNGateway and confirm that the SBC appears with Enabled set to True 47. Verify in the SBC interface that outgoing SIP OPTIONS requests receive 200 OK responses from Direct Routing and that the SBC returns 200 OK to incoming OPTIONS from Microsoft 47.
Rollback
To suspend SBC traffic temporarily for maintenance, set -Enabled $false using Set-CsOnlinePSTNGateway 39. Suggested rollback: Remove the SBC pairing.
Step 4 Connect Unified CM to the SBC for calls between platforms
Kept on-net over an internal SIP trunk between Unified CM and the SBC facing Teams
Do
In Unified CM, configure an interplatform trunk following Cisco's SIP trunk task flow: configure SIP profiles, configure a SIP trunk security profile, and configure the SIP trunk pointing to the SBC's internal destination address 974. Assign the SIP trunk security profile explicitly, because Unified CM assigns a nonsecure profile by default if omitted 6. Place the SIP trunk into a route group and add the route group to a route list, following Cisco's recommendation to point route patterns to route lists rather than directly to a gateway or trunk 87. Configure the SBC to route interplatform calls between Unified CM and the Teams Direct Routing interface 75.
Verify
Verify that the trunk shows active membership within the route group and route list in Unified CM administration 8. Suggested check: place a test call matching a test route pattern pointing to the route list and verify that the SBC logs an inbound SIP INVITE from Unified CM.
Rollback
Suggested rollback: Remove the test route pattern, remove the trunk from the route list and route group, and delete the SIP trunk and custom security profile in Unified CM.
Sent through the carrier across the PSTN
Do
In Unified CM, send calls matching a dial string to a gateway, trunk, or route list using route patterns 8. Maintain existing Unified CM PSTN route patterns so calls destined for numbers migrated to Teams are routed to the public carrier 8. WarmTransfer's reading of the sources is that interplatform calls routed without an internal trunk leave and re-enter via carrier trunks and incur carrier charges 26.
Verify
Verify that existing Unified CM route patterns cover the full E.164 dial strings assigned to users migrating to Teams 8.
Rollback
Suggested rollback: Maintain existing route patterns; no changes are required to reverse this step.
Step 5 Build Teams voice routing
Kept on-net over an internal SIP trunk between Unified CM and the SBC facing Teams
Do
Configure PSTN usages holding voice routes, dedicating a PSTN usage ahead of general routing to handle on-premises number ranges 5661. Under the on-premises usage, configure a voice route matching the Unified CM number ranges pointing to the SBC gateway, writing number patterns against the base number without any ;ext= component 5657. Under the general usage, configure a voice route covering external PSTN numbers 56. If a secondary SBC exists, configure it within the voice route at a lower priority to provide active-backup failover 55. Create a custom online voice routing policy and order the PSTN usages so the Unified CM usage appears first, because usages are evaluated sequentially and evaluation stops on the first match 5662. Do not apply these routes to the global (Org-wide default) policy, as Microsoft advises that global policy edits inadvertently affect all voice users 58.
Verify
Run Get-CsOnlineUser on a test user to verify that OnlineVoiceRoutingPolicy reflects the custom policy 63. Run Microsoft's Direct Routing self-diagnostic tool to validate the user configuration 63. Test calls to Unified CM ranges, verifying that numbers matching routes route correctly and recognizing that calls matching no route are dropped for users lacking a Calling Plan license 60.
Rollback
Suggested rollback: Remove the custom voice routing policy assignment from test users and delete the custom voice routes and PSTN usages.
Sent through the carrier across the PSTN
Do
Create a single PSTN usage containing a voice route that points external PSTN destinations to the Teams-facing SBC 56. WarmTransfer's reading of the sources is that calls placed by Teams users to numbers remaining on Unified CM will match this general PSTN route and egress to the carrier 26. If a secondary SBC exists, assign it a lower route priority within the voice route for backup redundancy 55. Build a custom online voice routing policy containing this PSTN usage rather than editing the global policy 5658.
Verify
Verify policy assignment on a test account using Get-CsOnlineUser and run the Teams admin center Direct Routing self-diagnostic tool 63. Verify that calls to a full Unified CM number egress via the SBC toward the carrier, noting that unmatched calls are dropped for users without Calling Plan licenses 60.
Rollback
Suggested rollback: Unassign the custom voice routing policy from test accounts and delete the voice route and PSTN usage.
Step 6 Make extension dialing work across both platforms
Kept on-net over an internal SIP trunk between Unified CM and the SBC facing Teams
Do
In the Teams tenant dial plan, add voice normalization rules using New-CsVoiceNormalizationRule and Set-CsTenantDialPlan to translate short extensions into full E.164 strings starting with + 1011. Position restrictive extension rules above less restrictive rules, as Teams processes dial plan rules from the top down and terminates on the first match 11. If short extensions arrive from Unified CM over the internal trunk, configure an inbound translation rule on the SBC gateway using InboundTeamsNumberTranslationRules to expand them into the user's assigned E.164 format for reverse number lookup 484951. If Unified CM requires numbers without a leading +, normalize to + in the dial plan and apply an outbound translation rule on the SBC gateway to strip the + 50.
Verify
Test normalized digit translation for a user with Test-CsEffectiveTenantDialPlan or the Teams admin center dial plan test tool 12. Verify that dialing a short Unified CM extension outputs the expected + prefixed E.164 string 1112.
Rollback
Suggested rollback: Remove the normalization rules using Set-CsTenantDialPlan and clear translation rules attached to the SBC gateway using Set-CsOnlinePSTNGateway.
Sent through the carrier across the PSTN
Do
In the Teams tenant dial plan, add voice normalization rules that expand dialed Unified CM internal extensions into full E.164 numbers representing the destination's external DID 1011. Order restrictive normalization rules above broader rules and ensure rules produce a leading + 11. If the connected PSTN carrier requires numbers without a leading +, configure an outbound translation rule on the SBC gateway to remove the + rather than altering the dial plan 50.
Verify
Inspect effective tenant dial plan output using Get-CsEffectiveTenantDialPlan and execute Test-CsEffectiveTenantDialPlan on an extension to verify that it expands to the target DID format 12.
Rollback
Suggested rollback: Remove the extension normalization rules from the tenant dial plan using Set-CsTenantDialPlan and remove any outbound translation rules from the SBC gateway.
Step 7 Configure emergency calling for Teams users before the first wave
Do
Configure a custom emergency call routing policy defining emergency dial strings and emergency dial masks for alternate numbers, ensuring dial strings and masks are unique within the policy 151376. Associate each emergency number with a PSTN usage pointing to a voice route that targets a dedicated emergency SIP trunk or an Emergency Location Identification Number (ELIN) gateway 17. Configure the emergency voice route pattern to match the emergency dial string without a leading +, because Teams Direct Routing clients do not prepend a + to emergency dial strings 14. For dynamic emergency calling across network sites, assign emergency policies to network sites to override user-level policies, and ensure emergency addresses carry validated geo codes 1677. In the United States, route calls to a certified 911 provider (Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service, or Inteliquent) and comply with MLTS regulations requiring direct 911 dialing without prefixes and provision of dispatchable location 13132. Maintain Unified CM emergency routing configurations for unmigrated users, as WarmTransfer's reading of the sources is that coexistence requires managing and testing emergency routing independently on each platform 25.
Verify
Suggested check: Place test emergency calls following your emergency service provider's test procedures from a test account at each network site, verifying that the call connects and delivers the expected location details, as listed in the Direct Routing verification checklist 37.
Rollback
Suggested rollback: Unassign the custom emergency call routing policy from user accounts and network sites, reverting accounts to global defaults; do not migrate production users if emergency validation fails.
Step 8 Enable a wave of users on Teams
Do
Enable migration-wave users according to Microsoft's sequence: assign a Teams Phone license, confirm the user is homed online, assign the telephone number and enable enterprise voice, configure direct-to-voicemail routing, and assign Teams Only coexistence mode 22. Assign the telephone number using Set-CsPhoneNumberAssignment with -PhoneNumberType DirectRouting, which automatically enables the user for Enterprise Voice 18. Format numbers in full E.164, appending ;ext= only if multiple users share a single base telephone number 19. Assign the UpgradeToTeams instance of TeamsUpgradePolicy to establish Teams Only mode 23. Grant the custom voice routing policy, custom dial plan, and custom emergency call routing policy to each user 637815.
Verify
Verify user configuration using Get-CsOnlineUser to ensure OnlineVoiceRoutingPolicy, dial plan, and Enterprise Voice flags are correctly set 63. Run the Teams Direct Routing self-diagnostic tool for the provisioned users 63.
Rollback
Suggested rollback: Unassign the custom voice routing and dial plan policies, and remove the phone number assignment using Teams administration tools.
Step 9 Move the wave's numbers on Unified CM
Kept on-net over an internal SIP trunk between Unified CM and the SBC facing Teams
Do
In Cisco Unified CM, remove the directory numbers assigned to the migrated users and create route patterns matching those numbers (or an entire migrated range) pointing to the route list configured in the interplatform trunk setup 87. Ensure that inbound PSTN carrier calls for migrated DIDs reach the SBC and route toward Teams Direct Routing, presenting called numbers matching the E.164 format assigned to users to allow successful reverse number lookup 49.
Verify
Suggested check: From a Unified CM phone, dial a migrated user's extension and verify that the call traverses the route list to ring the user's Teams client. Suggested check: Place an external PSTN call to the migrated user's DID and confirm that Teams rings and matches caller identification 49.
Rollback
Suggested rollback: Remove the Unified CM route patterns pointing to the route list and recreate the directory numbers on the original Unified CM user devices.
Sent through the carrier across the PSTN
Do
In Cisco Unified CM, remove the directory numbers for the migrated users so internal calls to those numbers fall through to existing PSTN route patterns 8. Ensure the PSTN carrier redirects the migrated DIDs to deliver calls to the SBC facing Teams Direct Routing 65.
Verify
Suggested check: From a Unified CM phone, dial the full PSTN number of a migrated user and verify that the call routes through the carrier and rings the Teams client 49. Suggested check: Dial the migrated DID from an external mobile or PSTN phone to confirm inbound call delivery to Teams.
Rollback
Suggested rollback: Restore the directory numbers on Unified CM and request that the PSTN carrier reroute the DIDs back to the Unified CM gateway trunks.
Step 10 Set up voicemail and forwarding for moved users
Do
Rely on Cloud Voicemail, which provisions automatically for licensed Direct Routing users without additional manual activation 24. Verify that users have mailboxes hosted on Exchange Online or Exchange Server, as Cloud Voicemail deposits messages into Exchange storage and does not support third-party email systems 54. Manage voicemail handling rules using Set-CsTeamsCallingPolicy -AllowVoicemail with AlwaysEnabled, AlwaysDisabled, or the default UserOverride 52. To route callers directly into a Teams user's voicemail from an external system or Unified CM without ringing the client, append opaque=app:voicemail to the SIP Request-URI sent to Teams 20. Note that call forwarding and simultaneous ring to PSTN numbers require Teams Phone licensing, and forwarded incoming PSTN calls try the ingress SBC first if it is also a candidate egress gateway 7959.
Verify
Run the Voicemail self-help diagnostic from the Teams admin center dashboard to confirm voicemail configuration for a migrated user 53. Suggested check: Place an unanswered test call to a migrated user and verify that a voicemail audio file arrives in the user's Exchange inbox 54.
Rollback
Suggested rollback: Reset the calling policy's AllowVoicemail setting to UserOverride using Set-CsTeamsCallingPolicy 52.
Step 11 Validate each wave before starting the next
Do
Execute Microsoft's Direct Routing deployment verification checklist, covering SBC connectivity health, bidirectional PSTN calling, emergency calling, SIP failover, policy assignments, and voice quality 37. Check FailoverTimeSeconds (which defaults to 10 seconds) against real answer times, as Microsoft warns that overly aggressive failover timers can drop calls on slower networks 40. Note that Teams media processors remain in the media path for voice applications such as auto attendants and call queues even if media bypass is active 30.
Verify
Verify that every check on Microsoft's verification list passes for a representative sample of users across the completed wave 37.
Rollback
Suggested rollback: If validation checks fail, pause subsequent wave migrations and roll back user assignments and Unified CM routing according to the user enablement and number migration procedures.
Step 12 Final cutover and decommission of the Unified CM path
Do
After migrating the final user wave, remove the Unified CM voice routes and PSTN usages from the custom Teams voice routing policy 5662. If numbers are later transitioned from Direct Routing to Microsoft Calling Plans or Operator Connect, unassign them from users and submit New-CsOnlineTelephoneNumberReleaseOrder to release them before porting 21. A single tenant supports combining multiple PSTN models simultaneously 80.
Verify
Run Get-CsOnlineUser to confirm that all tenant voice users reflect the final voice routing policy 63. Suggested check: Confirm that outbound PSTN and emergency calls continue to complete successfully after the Unified CM route is detached 37.
Rollback
Suggested rollback: Re-add the Unified CM PSTN usage and associated voice routes to the voice routing policy while the Unified CM cluster remains in service 5662.
Applicability
Applies to: Microsoft Teams Phone Direct Routing, Microsoft Teams, Cisco Unified Communications Manager, Microsoft Teams Phone, Multi-line telephone systems, Microsoft Teams Cloud Voicemail, and Cisco Unified Border Element. Deployments: on-premises, multi-tenant, dod, gcc, and gcc-high. Sources checked 2026-09-24. Emergency calling provider requirements and MLTS regulations apply specifically to deployments in the United States 131.
What remains uncertain
The specific vendor CLI commands and configuration syntax for programming dial peers, routing tables, and call classification on the Session Border Controller to split inbound DIDs between Unified CM and Teams are not covered by the sources below. Migration of legacy voicemail greetings, messages, and message waiting indicator states from Cisco Unity Connection to Cloud Voicemail is not covered by the sources below. Interplatform presence sharing, global directory synchronization, and shared-line appearance bridging across Cisco and Microsoft environments are not covered by the sources below. Specific carrier porting timelines and ordering procedures for shifting PSTN trunk capacity are not covered by the sources below. State-specific statutory variations and exact Code of Federal Regulations paragraph citations for MLTS compliance are not covered by the sources below.
See also
Depends on
- Microsoft teams phone — Reuses the Teams Phone licensing; PSTN-model; Direct Routing infrastructure and emergency-calling claims recorded for that topic.
Sources
- 1Microsoft certifies and supports Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service and Inteliquent as 911 service providers for Direct Routing, and may reject support cases that use a non-certified provider.Session Border Controllers certified for Direct Routing - Microsoft Teams · 911 service providers · Checked 2026-09-24
- 2Microsoft lists Cisco Unified Border Element as certified for Direct Routing, with and without media bypass, on ISR 1000, ISR 4000, CSR 1000V, ASR 1000 and Catalyst 8000 Edge platforms, supported from IOS XE 17.2.1r (17.3.2 on Catalyst 8000) with 17.6.1a recommended (17.3.3 on CSR 1000V).Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Cisco rows · Checked 2026-09-24
- 3Direct Routing certification applies to specific SBC firmware versions; firmware higher than the documented version is supported only while the major.minor version stays the same.Session Border Controllers certified for Direct Routing - Microsoft Teams · Introduction, Note on certification · Checked 2026-09-24
- 4Per-user coexistence modes other than Teams Only can be applied only to users homed in Skype for Business Server on-premises, and only cloud-homed users can have TeamsOnly mode.Set your coexistence and upgrade settings · Set upgrade options for a single user in your organization, step 3 · Checked 2026-09-24
- 5Cisco's application note for a CUBE co-resident with Unified CM describes two principal call routing designs and recommends routing all calls through Unified CM, regardless of destination, to centralize dial plan management.Direct Routing for Microsoft Phone System with Cisco Unified Communications Manager (UCM) via CUBE · search-result snippet only; section not identified · Checked 2026-09-24
- 6If no SIP trunk security profile is assigned to a SIP trunk, Unified CM assigns a nonsecure profile by default.System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks · Configure SIP Trunk Security Profile · Checked 2026-09-24
- 7Cisco recommends pointing route patterns at route lists and route groups rather than directly at a gateway, for routing flexibility and scalability.System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing · Configure Route Patterns, Note · Checked 2026-09-24
- 8In Unified CM, the system matches a dial string to a route pattern and uses it to send the call to a gateway, trunk or route list; route lists hold route groups in priority order, and route groups distribute calls to gateways and trunks.System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing · Call Routing Overview; route pattern, route list and route group sections · Checked 2026-09-24
- 9Cisco's Unified CM Release 15 SIP trunk task flow is: configure SIP profiles, configure a SIP trunk security profile, then configure the SIP trunk with those profiles and its destination addresses.System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks · SIP Trunk Configuration Task Flow · Checked 2026-09-24
- 10Microsoft's example tenant dial plan rule for organization extension dialing matches a short extension pattern such as ^(\d{3})$ and translates it to a full E.164 number, created with New-CsVoiceNormalizationRule and added with Set-CsTenantDialPlan.Create and manage dial plans · Using PowerShell, Using a PowerShell script · Checked 2026-09-24
- 11Teams evaluates a dial plan's normalization rules top down and uses the first match, so more restrictive rules must be placed above less restrictive ones, and Microsoft recommends that every rule produce a number starting with +.Create and manage dial plans · Using the Microsoft Teams admin center, Create a dial plan, step 4 Note · Checked 2026-09-24
- 12The effective dial plan for a user can be inspected with Get-CsEffectiveTenantDialPlan and tested against a dialed number with Test-CsEffectiveTenantDialPlan; the Teams admin center also offers a Test dial plan field.Create and manage dial plans · Create a dial plan step 6; Using single cmdlets · Checked 2026-09-24
- 13Emergency dial masks translate alternate emergency numbers (for example 112) to the policy's emergency dial string, and dial strings and masks must each be unique within a policy.Manage emergency call routing policies for Direct Routing · Create a custom emergency call routing policy, step 5b and Note · Checked 2026-09-24
- 14For Direct Routing, Teams clients no longer send emergency calls with a + before the emergency dial string, and the emergency dial string must be matched exactly by the voice route pattern.Manage emergency call routing policies for Direct Routing · Create a custom emergency call routing policy, step 5a and Note · Checked 2026-09-24
- 15For Direct Routing, an emergency call routing policy sets whether enhanced emergency services are enabled, which numbers are emergency numbers, and how emergency calls are routed; users get the global policy unless a custom one is assigned.Manage emergency call routing policies for Direct Routing · Introduction · Checked 2026-09-24
- 16If a Direct Routing user is at a network site that has an emergency call routing policy, the site's policy overrides the policy assigned to the user.Manage emergency call routing policies for Direct Routing · Introduction, paragraph on network sites · Checked 2026-09-24
- 17Each emergency number in the policy names a PSTN usage whose route should point to a SIP trunk dedicated to emergency calls or to an ELIN gateway that routes emergency calls to the nearest PSAP.Manage emergency call routing policies for Direct Routing · Create a custom emergency call routing policy, step 5c · Checked 2026-09-24
- 18For online-managed numbers, Set-CsPhoneNumberAssignment with -PhoneNumberType DirectRouting assigns the number and automatically enables the user for Enterprise Voice; the Teams admin center equivalent is Users > Manage users > Account > General information with phone number type Direct Routing.Enable users for Direct Routing · Configure the phone number and enable enterprise voice · Checked 2026-09-24
- 19Microsoft recommends, but does not require, full E.164 numbers; numbers may carry ;ext= extensions that are used to find the user when a base number matches several users, and the INVITE must then include the full number with extension.Enable users for Direct Routing · Configure the phone number and enable enterprise voice, Use PowerShell · Checked 2026-09-24
- 20A call arriving over Direct Routing is sent straight to the Teams user's voicemail, without notifying the user, when opaque=app:voicemail is attached to the Request-URI.Enable users for Direct Routing · Configure sending calls directly to voicemail · Checked 2026-09-24
- 21Before porting Direct Routing numbers to another Teams PSTN connectivity option, the numbers must be unassigned from users and then released from Microsoft's number inventory with New-CsOnlineTelephoneNumberReleaseOrder.Enable users for Direct Routing · Upload Direct Routing numbers to your tenant, Order history, Note · Checked 2026-09-24
- 22Microsoft's order for enabling a Direct Routing user is: create the user and assign a Teams Phone license, ensure the user is homed online, configure the phone number and enable enterprise voice, configure sending calls directly to voicemail, and assign Teams Only mode.Enable users for Direct Routing · Introduction, numbered list · Checked 2026-09-24
- 23Direct Routing requires users to be in Teams Only mode so that incoming calls land in the Teams client; this is done by assigning the UpgradeToTeams instance of TeamsUpgradePolicy.Enable users for Direct Routing · Assign Teams Only mode to users to ensure calls land in Microsoft Teams · Checked 2026-09-24
- 24After a Direct Routing user is licensed, Cloud Voicemail configuration for the user is automatic and needs no other configuration.Enable users for Direct Routing · Configure the phone number and enable enterprise voice, first paragraph · Checked 2026-09-24
- 25During coexistence, emergency calling has to be configured and tested separately on each platform, because Teams Direct Routing users follow Teams emergency call routing policies rather than Unified CM's emergency route patterns.inferredManage emergency call routing policies for Direct Routing · Derived from Introduction and Create a custom emergency call routing policy · Checked 2026-09-24
- 26If Teams voice routing has no route for Unified CM number ranges ahead of the general PSTN route, Teams calls to users still on Unified CM will match the PSTN route and leave through the carrier, so calls between the two platforms depend on carrier trunks and are subject to carrier call charges.inferredConfigure call routing for Direct Routing · Derived from Example 2 Note on PSTN usage order and the Example 2 routing table · Checked 2026-09-24
- 28To trial media bypass, Microsoft describes two trunks with different FQDNs pointing to the same SBC (different TLS signaling ports, same media ports, a certificate covering both names) and a separate voice routing policy for test users.Plan for media bypass with Direct Routing · Configure separate trunks for media bypass and non-media bypass · Checked 2026-09-24
- 29Media bypass is controlled per SBC with Set-CsOnlinePSTNGateway -MediaBypass; with bypass, media can flow directly between the Teams client and the SBC, but SIP signaling always flows through the Microsoft cloud.Plan for media bypass with Direct Routing · About media bypass with Direct Routing; Call flow if the user has direct access to the public IP address of the SBC · Checked 2026-09-24
- 30Teams Media Processors are always in the media path for voice applications such as Call Park, auto attendants and call queues, even when the trunk uses media bypass.Plan for media bypass with Direct Routing · Use of Media Processors and Transport Relays · Checked 2026-09-24
- 31US rules for multi-line telephone systems require that a user can dial 911 directly from any station, without any additional digit, code, prefix or post-fix.47 CFR § 9.16 - General obligations for MLTS (Cornell LII republication) · 47 CFR 9.16, direct 911 dialing provision · Checked 2026-09-24
- 32US MLTS rules require automated dispatchable location for fixed on-premises devices, and for non-fixed and off-premises devices automated dispatchable location where technically feasible, otherwise location from an end-user manual update (or enhanced location information off-premises).47 CFR § 9.16 - General obligations for MLTS (Cornell LII republication) · 47 CFR 9.16, dispatchable location provisions for installers, managers and operators · Checked 2026-09-24
- 33The SBC certificate should carry the SBC FQDN in the CN or SAN, be signed by a CA in the Microsoft Trusted Root Program, and include the Server Authentication EKU; RFC 2818-compliant wildcard certificates are supported.Plan Direct Routing · Public trusted certificate for the SBC · Checked 2026-09-24
- 34Microsoft instructs that the firewall allow signaling to and from all Microsoft Teams IP ranges (52.112.0.0/14 and 52.120.0.0/14 for commercial clouds), not only the addresses DNS returns.Plan Direct Routing · SIP signaling: FQDNs, Important note · Checked 2026-09-24
- 35Microsoft describes a common pattern of using Calling Plan or Operator Connect for PSTN calling while using Direct Routing for calls to third-party PBXs.Plan Direct Routing · Direct Routing with Calling Plan and Operator Connect · Checked 2026-09-24
- 36Microsoft's Direct Routing architecture shows one certified SBC connecting Teams Phone both to an existing PSTN carrier and to an existing PBX, and Microsoft names integration with third-party PBXs as a reason to choose Direct Routing.Plan Direct Routing · Why choose Direct Routing?; Direct Routing architecture · Checked 2026-09-24
- 37Microsoft's post-configuration checks for Direct Routing are: SBC reports a healthy connection, inbound and outbound PSTN calls work, emergency calling works if configured, failover between SIP connection points works, voice routing policies are assigned correctly, and call quality is acceptable.Plan Direct Routing · Verify your deployment · Checked 2026-09-24
- 38When MaxConcurrentSessions is set, the alerting system notifies at 90 percent or more of that value; without a value no alerts are generated.Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, MaxConcurrentSessions row · Checked 2026-09-24
- 39The SBC's Enabled setting turns the SBC on for outbound calls and can be used to take it temporarily out of service during maintenance; its default is False.Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, Enabled row · Checked 2026-09-24
- 40FailoverTimeSeconds (default 10) sends an outbound call that the gateway has not answered within that time to the next available trunk, and drops it if there is none; Microsoft warns this can drop calls unnecessarily on slow networks.Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, FailoverTimeSeconds row · Checked 2026-09-24
- 41With ForwardCallHistory turned on (default False), the Microsoft 365 proxy sends History-Info and Referred-By headers through the trunk.Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, ForwardCallHistory row · Checked 2026-09-24
- 42An SBC can be paired only if the domain part of its FQDN is a domain registered in the tenant other than *.onmicrosoft.com, a subdomain used in the FQDN must itself be registered, and the domain needs a user with an E3 or E5 license assigned.Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center, step 3; Connect the SBC to the tenant, Considerations · Checked 2026-09-24
- 43Mapping multiple IP addresses to the same SBC FQDN is not supported for Direct Routing.Connect your Session Border Controller (SBC) to Direct Routing · Connect the SBC to the tenant, Considerations · Checked 2026-09-24
- 44An SBC is paired with New-CsOnlinePSTNGateway using at minimum its FQDN, SIP signaling port, and Enabled set to true, or through Voice > Direct Routing > SBCs in the Teams admin center (PowerShell only for GCC High and DoD).Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center; Connect the SBC to the tenant · Checked 2026-09-24
- 45If the SBC's Send SIP options setting is turned off, the SBC is excluded from Direct Routing's monitoring and alert system; Microsoft highly recommends leaving it on.Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, SendSIPOptions row · Checked 2026-09-24
- 46Microsoft forces TLS 1.2 on the Direct Routing SIP interface, and the SBC must connect using one of four listed ECDHE-RSA AES-GCM or AES-CBC cipher suites.Connect your Session Border Controller (SBC) to Direct Routing · Connect the SBC to the tenant, Considerations · Checked 2026-09-24
- 47Microsoft's verification of a paired SBC is that Get-CsOnlinePSTNGateway lists it with Enabled True and that the SBC management interface shows 200 OK responses to its outgoing SIP OPTIONS and 200 OK replies to OPTIONS received from Direct Routing.Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection · Checked 2026-09-24
- 48Microsoft's example translates a four-digit called number arriving from the SBC into E.164 with an InboundTeamsNumberTranslationRules entry matching ^(\d{4})$, so a caller who dials only four digits still reaches the Teams user.Translate phone numbers for Direct Routing · Example SBC configuration; Example 2: Inbound call to a four-digit number · Checked 2026-09-24
- 49Inbound Direct Routing calls reach a Teams user by reverse number lookup on the called number, and an inbound translation rule on the SBC can rewrite a called number that does not match the format assigned to users.Translate phone numbers for Direct Routing · Route-based number translations - for inbound calls · Checked 2026-09-24
- 50To avoid double normalization, Microsoft recommends that Direct Routing customers normalize numbers to a leading + with dial plans and, if the SBC needs another format, remove the + with a route-based translation rule on the SBC.Translate phone numbers for Direct Routing · Route-based number translations - for outbound calls, Note · Checked 2026-09-24
- 51Number translation rules are applied per SBC in the order they are listed, are managed with the *-CsTeamsTranslationRule cmdlets and attached through four Inbound/Outbound Teams/PSTN parameters of New- or Set-CsOnlinePSTNGateway, and are capped at 400 rules in total.Translate phone numbers for Direct Routing · Considerations; Configuring translation rules with PowerShell · Checked 2026-09-24
- 52Set-CsTeamsCallingPolicy -AllowVoicemail controls voicemail routing: AlwaysEnabled sends unanswered calls to voicemail after 30 seconds, AlwaysDisabled never routes to voicemail, and UserOverride (the default) follows each user's forwarding and unanswered settings.Set up Cloud Voicemail · Control routing of calls to Cloud Voicemail, Using PowerShell · Checked 2026-09-24
- 53Microsoft provides a Voicemail self-help diagnostic, reached from the Teams admin center dashboard, that checks whether a named user is correctly configured to receive voicemail.Set up Cloud Voicemail · Diagnosing issues with Voicemail · Checked 2026-09-24
- 54Cloud Voicemail delivers messages to the user's Exchange mailbox (Exchange Online or Exchange Server) and does not support third-party email systems.Set up Cloud Voicemail · Introduction; Cloud Voicemail storage · Checked 2026-09-24
- 55Voice routes carry priorities so a lower-priority route's SBCs are tried when the higher-priority route's SBCs are unavailable, while the SBCs listed within a single route are tried in random order.Configure call routing for Direct Routing · Example 1: Voice routing with one PSTN usage · Checked 2026-09-24
- 56Direct Routing call routing is made up of voice routing policies (containers of PSTN usages assigned to users), PSTN usages (containers of voice routes), voice routes (a number pattern plus a set of online PSTN gateways) and online PSTN gateways (pointers to SBCs).Configure call routing for Direct Routing · Call routing overview · Checked 2026-09-24
- 57When a called number contains an extension (for example +1425XXXXXXX;ext=YYY), the voice route number pattern is matched only against the number without the extension.Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 2 · Checked 2026-09-24
- 58If the global (Org-wide default) online voice routing policy is configured, every voice-enabled user inherits it, which can send Calling Plan and Operator Connect users' PSTN calls to a Direct Routing trunk; Microsoft advises custom policies assigned to individual users instead.Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 1 · Checked 2026-09-24
- 59When an incoming PSTN call is forwarded or transferred and its ingress SBC is also a candidate egress SBC, Direct Routing ignores that SBC's route priority and tries it first.Configure call routing for Direct Routing · Example 1, Note following the summary table · Checked 2026-09-24
- 60For a user with Teams Phone but no Calling Plan license, a call whose number matches no voice route in the user's policy is dropped.Configure call routing for Direct Routing · Example 1, Note following the first diagram · Checked 2026-09-24
- 61Microsoft's example keeps a dedicated PSTN usage ahead of the International usage specifically to preserve special handling of certain number ranges as local or on-premises calls routed to designated SBCs.Configure call routing for Direct Routing · Example 2, Using the Microsoft Teams admin center, Step 3 · Checked 2026-09-24
- 62PSTN usages in a voice routing policy are applied in order and once a match is found in one usage the later usages are never evaluated, so a more specific usage must be placed before a catch-all usage.Configure call routing for Direct Routing · Example 2: Voice routing with multiple PSTN usages, Note · Checked 2026-09-24
- 63A voice routing policy assignment can be verified with Get-CsOnlineUser selecting OnlineVoiceRoutingPolicy, and Microsoft provides a self-diagnostic that checks whether a user is correctly configured for Direct Routing (not available in Microsoft 365 Government, 21Vianet or Germany).Configure call routing for Direct Routing · Example 1, Using PowerShell, Step 4; Run a Self-diagnostics tool · Checked 2026-09-24
- 64Microsoft describes Teams Phone as its technology for call control and PBX capabilities delivered in the Microsoft 365 cloud.What is Teams Phone · What is Teams Phone, opening paragraph · Checked 2026-09-24
- 65Direct Routing lets an organization use any PSTN operator by connecting it through a certified SBC that is procured, installed and managed by the customer, an integrator or a Direct-Routing-as-a-Service provider.PSTN connectivity options · PSTN connectivity options, bullet 'Direct Routing' · Checked 2026-09-24
- 66To use PSTN telephony with Teams Phone, a user account must be licensed with the Teams Phone application and also be equipped with a PSTN solution from a PSTN service provider.PSTN connectivity options · PSTN connectivity options, section 'What is the Public Switched Telephone Network (PSTN)?' · Checked 2026-09-24
- 67Where any Microsoft 365 E5 license is used, it is not necessary to also assign the stand-alone Microsoft Teams Phone Standard license.Teams Phone licensing · Teams Phone licensing, section 'Licensing Teams Phone - for end users', paragraph after the example list · Checked 2026-09-24
- 68Microsoft Teams Phone Standard and Teams Phone with Calling Plan each require a prerequisite license; the listed prerequisites include Microsoft 365 Business Basic, Business Standard, Business Premium, F1, F3, E3 and A3, Microsoft Teams EEA, Microsoft Teams Enterprise, Microsoft Teams Essentials (AAD Identity), and Office 365 F3, E1, E3, A1 and A3.Teams Phone licensing · Teams Phone licensing, section 'Licensing Teams Phone - for end users', prerequisite license table rows 1 and 3 · Checked 2026-09-24
- 69Direct Routing requires a Microsoft-certified SBC, PSTN trunks to it, users homed online, a public IP, an SBC FQDN in a verified tenant domain (not *.onmicrosoft.com) with public DNS, and a publicly trusted TLS certificate.Plan Direct Routing · Plan Direct Routing, section 'Infrastructure requirements' table and section 'SBC domain names' · Checked 2026-09-24
- 70Direct Routing is not supported in Islands coexistence mode.Plan Direct Routing · Plan Direct Routing, section 'Licensing requirements', Note · Checked 2026-09-24
- 71Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used, expects the SBC vendor to investigate first and escalate, and may decline support requests involving non-certified SBCs.Plan Direct Routing · Plan Direct Routing, sections 'Supported Session Border Controllers (SBCs)' and 'Support boundaries' · Checked 2026-09-24
- 72For Microsoft 365, Office 365 and GCC, the SBC connects to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com in priority order over SIP/TLS to port 5061; GCC High uses sip.pstnhub.gov.teams.microsoft.us and DoD uses sip.pstnhub.dod.teams.microsoft.us.Plan Direct Routing · Plan Direct Routing, sections 'SIP signaling: FQDNs', 'SIP signaling: GCC High', 'SIP signaling: DoD', 'SIP signaling ports' · Checked 2026-09-24
- 73Direct Routing media between Microsoft media processors and the SBC uses UDP/SRTP ports 3478-3481 and 49152-53247 in both directions, and Microsoft recommends at least two media ports per concurrent call on the SBC.Plan Direct Routing · Plan Direct Routing, section 'Media ports' table and Tip · Checked 2026-09-24
- 74A Cisco Unified Communications Manager SIP trunk can be assigned up to 16 different destination addresses using IPv4 or IPv6 addressing, fully qualified domain names, or a single DNS SRV record.System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks · Configure Trunks > SIP Trunk Overview · Checked 2026-09-21
- 75Cisco documents Cisco Unified Border Element as able to bridge enterprise and PSTN with cloud calling services such as Webex Calling and MS Teams Direct Routing, and describes CUBE as a network-to-network demarcation interface for signalling and media interworking, address and port translation, billing, security, quality of service, call admission control and bandwidth management.Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Overview of Cisco Unified Border Element · Overview of Cisco Unified Border Element, capability list · Checked 2026-09-21
- 76Direct Routing requires specific emergency call routing policies, whereas with the other PSTN options the carrier handles much of the emergency call routing configuration.Plan and manage emergency calling · Plan and manage emergency calling, section 'Emergency call routing' · Checked 2026-09-24
- 77To assign an emergency location to a network identifier for dynamic emergency calling, the emergency address must be validated and carry a geo code; addresses created with the Teams admin center map search get both automatically.Plan and manage emergency calling · Plan and manage emergency calling, sections 'Emergency address validation' and 'Emergency address geo codes', Important block · Checked 2026-09-24
- 78Tenant dial plans are managed with New-CsTenantDialPlan, Set-CsTenantDialPlan and Grant-CsTenantDialPlan, and the result for a given user and dialled number is checked with Get-CsEffectiveTenantDialPlan and Test-CsEffectiveTenantDialPlan.Create and manage dial plans · Using PowerShell > Using single cmdlets · Checked 2026-09-21
- 79Placing calls by extension or PSTN number, forwarding and simultaneous ring to PSTN numbers, dial plans, emergency calling, unassigned number routing and call blocking of PSTN numbers are all listed as requiring Teams Phone.Teams Phone features · Teams Phone features, table 'Teams calling features', rows 'Call answer/initiate (by extension or PSTN phone number)', 'Call forwarding options and simultaneous ring', 'Dial plans', 'Emergency calling', 'Unassigned number routing', 'Call blocking' · Checked 2026-09-24
- 80A single Teams tenant can have more than one PSTN integration, and Microsoft states that any combination of PSTN solutions is supported.What is Teams Phone · What is Teams Phone, add-on options list, PSTN operator solution sub-bullets · Checked 2026-09-24
Documents
47 CFR § 9.16 - General obligations for MLTS (Cornell LII republication)
Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Overview of Cisco Unified Border Element
Configure call routing for Direct Routing
Connect your Session Border Controller (SBC) to Direct Routing
Create and manage dial plans
Direct Routing for Microsoft Phone System with Cisco Unified Communications Manager (UCM) via CUBE
Enable users for Direct Routing
Manage emergency call routing policies for Direct Routing
Plan and manage emergency calling
Plan Direct Routing
Plan for media bypass with Direct Routing
PSTN connectivity options
Session Border Controllers certified for Direct Routing - Microsoft Teams
Set up Cloud Voicemail
Set your coexistence and upgrade settings
System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing
System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks
Teams Phone features
Teams Phone licensing
Translate phone numbers for Direct Routing
What is Teams Phone
Cite this page
APA
WarmTransfer. (2026, September 24). Building a hybrid Unified CM and Teams Phone environment for a phased migration. WarmTransfer. https://warmtransfer.net/guides/cucm-teams-hybrid-build
BibTeX
@misc{warmtransfer-cucm-teams-hybrid-build,
title = {Building a hybrid Unified CM and Teams Phone environment for a phased migration},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cucm-teams-hybrid-build},
note = {Verified 2026-09-24}
}