Migrations · guide

CUCM to Teams Phone migration

Cisco Unified Communications Manager to Microsoft Teams Phone

Verified 2026-09-21 · 156 sources · tier 2–6

For Voice engineers and unified-communications administrators migrating telephony from CUCM to Microsoft Teams Phone..

Microsoft positions Microsoft Teams Phone as a cloud private branch exchange technology able to replace an existing PBX system 138. A Teams Phone licence and a public switched telephone network solution are managed separately: the licence supplies call control while the PSTN solution delivers numbers and dial tone 87.

Before you start

  • Confirm that your tenant contains the required licences: Microsoft Teams and Microsoft 365 Phone System for all voice users (included with any Microsoft 365 E5 licence), separate Calling Plan licences if Microsoft supplies the PSTN access, Microsoft Teams Shared Device licences for shared hardware, and Microsoft Teams Phone Resource Account licences for auto attendants and queues 50 51 52.
  • WarmTransfer's reading of the sources is that Microsoft documents no automated conversion tool for importing a dial plan from Cisco Unified Communications Manager, meaning routing components, tenant dial plans, PSTN usages, voice routes, and translation rules must be planned and rebuilt manually 67.
  • In CUCM, a route pattern directs a matching dial string to a gateway or route list, a route list prioritises paths, and a route group distributes calls to gateways and trunks 15.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

How do migrated users reach the PSTN?
How will user populations cut over?
What is the plan for Cisco IP desk phones?
How will emergency calls be routed?
What survivability mechanism protects branch calling during cloud outages?

Five questions. One permanent page you can send to your manager.

Step 1 Validate PSTN architecture and prerequisites

Keep carrier trunks using Cisco CUBE as the SBC

Do

Review the session border controller hardware against supported platforms: Cisco Unified Border Element is certified for Microsoft Teams Direct Routing on ISR 1000 Series, ISR 4000 Series, CSR 1000V, ASR 1000 Series, and Catalyst 8000 Edge Platforms 12. Verify that the CUBE firmware runs at least IOS XE Amsterdam 17.2.1r (17.6.1a recommended; 17.3.3 for CSR 1000V; 17.3.2 upwards for Catalyst 8000 Edge), noting that Microsoft supports higher versions as long as the major.minor release remains unchanged 13. Ensure the deployment meets all Direct Routing infrastructure prerequisites: certified SBC, connected PSTN trunks, a tenant hosting online-homed Teams users, a registered custom domain not ending in *.onmicrosoft.com, public IP, public DNS record, and a trusted public certificate 30. WarmTransfer's reading of the sources is that Cisco is not listed in Microsoft's certified vendor table for Local Media Optimization 14.

Verify

Suggested check: review the running configuration of each border element to confirm platform model and release match certification lists.

Rollback

Suggested rollback: retain existing trunks and abandon deployment.

Keep carrier trunks on a non-Cisco certified SBC

Do

Select an SBC model and firmware version from Microsoft's certified list, noting that Microsoft supports Direct Routing only on certified SBCs, reserves the right to decline cases involving non-certified hardware, and is not accepting new certification nominations until further notice 24 114. Verify the infrastructure prerequisites: certified SBC, PSTN trunks, online-homed users, registered custom domain, public IP, public DNS, and trusted certificate 30. Establish support channels with the SBC vendor, as Microsoft requires Direct Routing support incidents to be submitted to the SBC vendor first and accompanied by an investigation report 121.

Verify

Suggested check: verify that the chosen SBC make and firmware version appear on the certified Direct Routing list.

Rollback

Suggested rollback: leave routing directed to the existing call control system.

Acquire PSTN access from Microsoft Calling Plan

Do

Confirm Microsoft Teams Calling Plan availability in the required operational regions, noting that Calling Plan bundles PSTN access, numbers, technical support, and US emergency screening under a 99.999% reliability SLA 4. Assign Calling Plan licences to users who require outbound PSTN dialling, alongside Teams Phone licences 51. Note that Calling Plan supports subscriber numbers, Audio Conferencing numbers, and voice application numbers for call queues and auto attendants 82.

Verify

Suggested check: inspect licence assignment in admin center for all designated pilot users.

Rollback

Suggested rollback: remove assigned Calling Plan licences in admin center.

Mix Direct Routing with Calling Plan across populations

Do

Designate user populations and functions across connectivity options, using Direct Routing for legacy PBX interop, analog devices, or specialized routing, and Calling Plan for standard users 29. Note that Calling Plan, Operator Connect, and Direct Routing support subscriber, conferencing, and application numbers, while Teams Phone Mobile supports only user phone numbers 82. Licence shared hardware with Microsoft Teams Shared Device licences, meeting spaces with Teams Rooms Pro, and voice applications with Microsoft Teams Phone Resource Account licences 52.

Verify

Suggested check: check user licensing and device SKU mapping across each designated migration group.

Rollback

Suggested rollback: unassign newly added user licences and re-register analog lines to the PBX.

Step 2 Inventory CUCM dial patterns and extensions

Do

In CUCM, a route pattern directs a matching dial string to a gateway or route list, a route list prioritises paths, and a route group distributes calls to gateways and trunks 15. Note that CUCM translation patterns rewrite digits and route calls using their internal calling search space 17. Inventory real DIDs versus non-routable internal extensions, noting that Teams routes inbound calls to users by performing Reverse Number Lookup on the received dialled number-string 140.

Verify

Suggested check: verify that all exported directory numbers are mapped to a target destination or tagged to remain on-premises.

Rollback

Suggested rollback: retain exported inventory files as archival reference.

Step 3 Configure network perimeter, domains, and certificates

Keep carrier trunks using Cisco CUBE as the SBC

Do

Register the FQDN domain of the CUBE in the tenant, ensuring the domain does not use *.onmicrosoft.com 111. Verify that a user with an assigned E3 or E5 licence exists in that domain and that the domain's authentication type is set to Managed, or gateway pairing will fail 108. Assign a single public IP to the FQDN, as multiple IPs per FQDN are not supported 118. Install a public certificate whose CN or SAN matches the SBC FQDN, issued by a Certificate Authority in the Microsoft Trusted Root Program with Server Authentication EKU 107. Configure TLS 1.2 on CUBE using one of the four supported ECDHE-RSA cipher suites in AES 128 or 256 CBC or GCM mode 120. Open firewall ports for SIP/TLS signaling over port 5061 outbound to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com, and sip3.pstnhub.microsoft.com across all Teams IP ranges (52.112.0.0/14 and 52.120.0.0/14) and inbound to the configured CUBE port 131 26 49. Open media ports towards Microsoft Media Processors 31.

Verify

Suggested check: test TLS handshakes to destination port on Direct Routing proxies and verify domain status.

Rollback

Suggested rollback: delete created firewall rules and revert DNS records.

Keep carrier trunks on a non-Cisco certified SBC

Do

Register the domain portion of the SBC FQDN in the tenant, ensuring it is not *.onmicrosoft.com 111. Create a user with that domain holding an E3 or E5 licence, and set the domain authentication to Managed 108. Install a certificate issued by a Microsoft Trusted Root Program CA with the SBC FQDN in the CN or SAN 107. Map a single IP to the SBC FQDN 118. Enable TLS 1.2 using supported ECDHE-RSA ciphers 120. Allow SIP/TLS traffic outbound on port 5061 to the Microsoft SIP proxy FQDNs across all Microsoft Teams IP ranges 131 26 49.

Verify

Suggested check: check certificate chain validation on the SBC management interface.

Rollback

Suggested rollback: disable perimeter firewall rules for Direct Routing signaling.

Acquire PSTN access from Microsoft Calling Plan

Do

Maintain an existing assignment of emergency locations for users in the United States and Canada if a Calling Plan licence is in place before port completion, or assign emergency locations when numbers transfer in 85.

Verify

Suggested check: inspect user account usage locations in the admin center.

Rollback

Suggested rollback: revert tenant domain and usage location settings if required.

Mix Direct Routing with Calling Plan across populations

Do

For Direct Routing populations, complete domain registration, licensed user provisioning, TLS 1.2 ECDHE-RSA configuration, public CA certificate installation, and firewall openings on port 5061 across all Teams IP ranges 111 108 107 120 131 49. For Calling Plan users, maintain emergency locations and licences before port completion 85.

Verify

Suggested check: confirm domain verification and validate network connectivity to Direct Routing signaling endpoints.

Rollback

Suggested rollback: remove Direct Routing perimeter firewall rules.

Step 4 Establish PSTN connectivity

Keep carrier trunks using Cisco CUBE as the SBC

Do

Following Microsoft's four-step Direct Routing deployment sequence (connect SBC, enable users, configure routing, translate numbers), pair CUBE to the tenant using PowerShell 33:

New-CsOnlinePSTNGateway -Fqdn <cube_fqdn> -SipSignalingPort <port> -MaxConcurrentSessions <limit> -Enabled $true

116. Keep SendSIPOptions enabled (the default) so the gateway remains active in Microsoft monitoring and alerting 117. Set the SIP OPTIONS interval per trunk endpoint to the published requirement, which as written sets bounds that read as mutually inconsistent, one transaction every 60 seconds and one every 180 seconds, so confirm the current figure at the source before setting it 115. Set ForwardCallHistory and ForwardPai to $true if upstream PBX or carrier services require History-Info, Referred-By, or P-Asserted-Identity headers 110. Configure supported codecs (SILK, G.711, G.722, G.729, or AMR-WB in non-bypass) and avoid re-targeting media mid-call, as Teams negotiates the change but will not transmit audio to the new IP 25 113.

Verify

Run Get-CsOnlinePSTNGateway -Identity <cube_fqdn> to confirm Enabled is True, and check CUBE logs to confirm both incoming and outgoing SIP OPTIONS receive 200 OK responses 122.

Rollback

Disable outbound traffic by running Set-CsOnlinePSTNGateway -Identity <cube_fqdn> -Enabled $false, or remove the gateway entry with Remove-CsOnlinePSTNGateway 116.

Keep carrier trunks on a non-Cisco certified SBC

Do

Execute the Direct Routing deployment flow 33. Pair the certified SBC with New-CsOnlinePSTNGateway setting -Fqdn, -SipSignalingPort, -MaxConcurrentSessions, and -Enabled $true 116. Keep SendSIPOptions enabled for alerting and monitoring 117, and set the OPTIONS interval to the published requirement, which as written sets bounds that read as mutually inconsistent, one transaction every 60 seconds and one every 180 seconds, so confirm the current figure at the source first 115. Ensure offered codecs match SILK, G.711, G.722, G.729, or non-bypass AMR-WB 25.

Verify

Verify that Get-CsOnlinePSTNGateway displays Enabled : True and that bidirectional 200 OK responses occur for SIP OPTIONS 122.

Rollback

Run Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -Enabled $false to suspend the gateway 116.

Acquire PSTN access from Microsoft Calling Plan

Do

Submit a port request, ensuring the billing telephone number matches losing service provider records exactly and verifying that any account freeze has been removed to avoid rejection 83. If porting numbers previously registered in Direct Routing, unassign them and release them from tenant inventory using New-CsOnlineTelephoneNumberReleaseOrder prior to the port event 81.

Verify

Check that the port request transitions to Approved (FOCAccepted) in Order history, and confirm Calling Plan licences and emergency locations are assigned to target users in the US and Canada prior to completion 85.

Rollback

Cancel the port request prior to the firm order commitment date 83.

Mix Direct Routing with Calling Plan across populations

Do

Pair the SBC for Direct Routing populations using New-CsOnlinePSTNGateway 116. For Calling Plan users, initiate carrier port requests ensuring matching billing telephone numbers and lifting account freezes 83. Release any Direct Routing numbers with New-CsOnlineTelephoneNumberReleaseOrder before porting them to Calling Plan 81.

Verify

Confirm Direct Routing gateway shows Enabled : True via Get-CsOnlinePSTNGateway 122, and confirm port orders display Approved (FOCAccepted) status 85.

Rollback

Disable the gateway using Set-CsOnlinePSTNGateway -Enabled $false and cancel pending port orders 116 83.

Step 5 Configure voice routing policies

Keep carrier trunks using Cisco CUBE as the SBC

Do

Create Direct Routing call routing components: online voice routing policies containing PSTN usages, PSTN usages containing voice routes, and voice routes linking number patterns to online PSTN gateways 90. Execute the PowerShell cmdlet sequence: create the usage with Set-CsOnlinePstnUsage, define routes with New-CsOnlineVoiceRoute (specifying -NumberPattern, -OnlinePstnGatewayList, -Priority, and -OnlinePstnUsages), create custom policies with New-CsOnlineVoiceRoutingPolicy, and assign them using Grant-CsOnlineVoiceRoutingPolicy 88. Arrange PSTN usages deliberately, as usages evaluate in sequential order and evaluation stops at the first match 96. To configure active/backup CUBE routing, define two separate voice routes with different priorities, because multiple SBCs listed within a single voice route are selected in random order 94. Assign routing policies directly to specific users rather than altering the global policy, to prevent Calling Plan users from inadvertently sending calls to CUBE 91. Configure a catch-all voice route, as calls made by users lacking a Calling Plan licence will be dropped if no pattern matches 93.

Verify

Check policy assignment with Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy 88. Run the Direct Routing self-diagnostics tool in the Microsoft 365 admin center (not supported in Government, 21Vianet, or Germany clouds) 95.

Rollback

Unassign the policy with Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null and remove routes with Remove-CsOnlineVoiceRoute 88.

Keep carrier trunks on a non-Cisco certified SBC

Do

Build the routing policy hierarchy using Set-CsOnlinePstnUsage, New-CsOnlineVoiceRoute, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy 90 88. Sequence usages deliberately to control route evaluation 96. Configure route priorities rather than multi-SBC route lists to establish primary and backup paths 94. Avoid modifying the global voice routing policy to prevent tenant-wide inheritance 91, and define catch-all patterns so unmatched calls are not dropped 93.

Verify

Confirm user policy assignment via Get-CsOnlineUser and execute the tenant self-diagnostics tool 88 95.

Rollback

Run Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null to remove custom routing 88.

Acquire PSTN access from Microsoft Calling Plan

Do

Do not assign custom online voice routing policies or modify the global policy, ensuring Calling Plan users route through Microsoft PSTN infrastructure without diversion to external trunks 91. Assign numbers directly to users and voice application resource accounts 82.

Verify

Run Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy and confirm the value is empty 88. Suggested check: place an outbound call to an external number from a test user client.

Rollback

If a voice routing policy was assigned in error, clear it with Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null 88.

Mix Direct Routing with Calling Plan across populations

Do

Configure PSTN usages, voice routes, and custom online voice routing policies strictly for the Direct Routing user population 90 88. Leave the global voice routing policy unassigned to prevent Calling Plan users from inheriting trunk routes 91. Note that if a user holds both a voice routing policy and a Calling Plan licence, Teams evaluates the voice route policy first and only routes via Calling Plan if no route patterns match 93.

Verify

Run Get-CsOnlineUser across both populations to confirm Direct Routing users hold the custom policy while Calling Plan users have no assigned policy 88.

Rollback

Clear voice routing policies from affected users with Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null 88.

Step 6 Rebuild dial plan normalization and trunk translation rules

Do

Order normalization rules top-down with restrictive patterns above permissive patterns, because Teams terminates traversal at the first matching rule 21. Manage dial plans using New-CsTenantDialPlan, Set-CsTenantDialPlan, and Grant-CsTenantDialPlan 19. To avoid double normalization, Microsoft recommends normalizing numbers to include a plus sign in the dial plan and removing the plus sign using route-based translation rules if an SBC or carrier requires local digit formats 20. Create SBC translation rules with New-CsTeamsTranslationRule and attach them to the gateway using InboundTeamsNumberTranslationRules, InboundPSTNNumberTranslationRules, OutboundTeamsNumberTranslationRules, or OutboundPSTNNumberTranslationRules 139. Note that translation rules apply at the SBC level in the order listed 142. Apply inbound translation rules where incoming carrier strings diverge from user assigned numbers, because Teams matches inbound calls using Reverse Number Lookup on the received string 140. Maintain total translation rules within the 400-rule limit, with maximum pattern lengths under 1024 symbols and translation lengths under 256 symbols 141. Verify user usage locations, because when no dial plan rule matches, the Teams service dial plan automatically prepends the country code matching the dialling user's usage location 22.

Verify

Test dial plan normalization using PowerShell:

Test-CsEffectiveTenantDialPlan -DialedNumber <digits> -Identity <upn>

19. Suggested check: examine SBC SIP signalling to verify that outbound Request-URIs reflect the formatting expected by the carrier.

Rollback

Detach translation rules using Set-CsOnlinePSTNGateway with empty rule lists 139. Revert user dial plans with Grant-CsTenantDialPlan -Identity <upn> -PolicyName $null 19.

Step 7 Configure call routing between CUCM and Teams

Phased coexistence with parallel call routing

Do

Configure a SIP trunk on CUCM pointing to CUBE following Cisco's documented task order: build the SIP profile, configure the SIP trunk security profile (setting TLS encryption and digest authentication), and then configure the SIP trunk 18. Assign up to 16 destination addresses per CUCM SIP trunk using IPv4, IPv6, FQDNs, or a single DNS SRV record 16. Cisco documents CUBE as bridging enterprise and PSTN networks to cloud services including MS Teams Direct Routing, and Cisco's interoperability portal publishes dedicated application notes for Direct Routing with CUCM via CUBE 10 5. For each migrated user, decommission the directory number on CUCM and add a translation pattern that rewrites the internal extension to E.164 and reroutes it with a calling search space towards a route pattern pointing to CUBE 17 15. In Teams, define voice routes directing unmigrated extension ranges to the CUBE gateway 88. Note that on transferred or forwarded calls where the ingress SBC is also a valid egress SBC, Direct Routing prioritises that ingress SBC regardless of route priority values 92.

Verify

Suggested check: place bidirectional test calls between unmigrated desk phones and migrated clients, test calls between migrated clients and external PSTN numbers, and transfer an inbound call back out to verify ingress SBC handling.

Rollback

Delete the translation pattern on CUCM and restore the directory number to service 17.

Site-by-site flash cutover in scheduled maintenance windows

Do

Establish the CUCM-to-CUBE trunk following the profile, security profile, and trunk task order 18. Configure site-level route patterns on CUCM pointing to a route list containing the CUBE trunk 15, keeping them in an isolated partition until cutover. Pre-configure Teams voice routes and gateway translation rules matching site number blocks 88 139.

Verify

Suggested check: execute a pre-cutover rehearsal using a non-production test number routed through the trunk to the cloud and back.

Rollback

Move site route patterns back to the isolated partition in CUCM and restore local device line assignments 15.

Step 8 Configure emergency calling

Certified Emergency Routing Service provider

Do

Configure emergency call routing policies, which Direct Routing requires because emergency call paths depend on client type, country network, and PSTN model 35. Enable PIDF-LO on the gateway by setting Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -PidfloSupported $true or toggling the setting in Teams admin center so location data is included in outgoing emergency INVITEs 41. Contract a certified Direct Routing emergency provider: Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service, or Inteliquent, noting Microsoft may reject support cases involving uncertified providers 105. Configure trusted IP addresses and network sites for dynamic emergency enablement and security desk notifications 36. Define Location Information Service entries, noting LIS resolves client locations by checking WAP, Ethernet switch and port, Ethernet switch, and subnet in order 39. Assign emergency calling policies for security desk alerts, noting a policy assigned to a network site overrides a user policy when the user is located at that site 42 44.

Verify

Allow up to four hours for network settings changes to propagate to clients 43. Coordinate a live test call with the ERS provider, noting that the 933 test dial string applies to Calling Plan, Operator Connect, and Teams Phone Mobile, not Direct Routing 45.

Rollback

Set PidfloSupported to $false with Set-CsOnlinePSTNGateway 41. Suggested rollback: revert emergency routing on the border element to route outbound emergency calls through existing on-premises trunks.

SBC ELIN application

Do

Configure an Emergency Location Identification Number application on the SBC as the documented alternative to an ERS provider 37. Set PidfloSupported to $true on the gateway to pass location attributes to the SBC 41. Note that Microsoft's certified SBC table marks Cisco CUBE as 911-service-provider capable but leaves the ELIN-capable column blank 11. Configure trusted IP addresses and network sites for dynamic location discovery and security desk notifications 36. Populate LIS network identifiers (WAP, switch/port, switch, subnet) 39, and assign emergency call routing policies 35.

Verify

Allow up to four hours for network setting propagation 43. Suggested check: place a test emergency call from each designated ELIN zone to confirm the delivered ELIN matches the floor and building with the test operator.

Rollback

Suggested rollback: reroute emergency patterns on the SBC back to PBX route patterns.

Microsoft-managed emergency routing

Do

Assign validated emergency addresses with geocodes to user phone numbers during assignment 85 38. Configure trusted IP addresses for dynamic emergency calling and network sites for dynamic security desk notification 36. Apply emergency calling policies to define emergency dial strings and notification targets, noting site policies override user policies when the user is on site 42 44.

Verify

In the United States and Canada, place a test call to 933 from a client at the site to verify that the automated service echoes the assigned calling line ID and registered address 45.

Rollback

Reassign emergency addresses or modify emergency calling policies via the Teams admin center 42.

Step 9 Pilot user migration

Do

Assign the UpgradeToTeams instance of TeamsUpgradePolicy to pilot users to place them in Teams Only mode, which is required for Direct Routing so inbound calls land in the Teams client 150. Direct Routing is not supported in Islands mode 32. If pilot users originate from an on-premises Skype for Business deployment, verify that RegistrarPool is homed in infra.lync.com and clear any existing on-premises LineUri with Set-CsUser -LineUri $null prior to assigning numbers online 146. Assign phone numbers and enable Enterprise Voice using PowerShell:

Set-CsPhoneNumberAssignment -Identity <upn> -PhoneNumber <e164_number> -PhoneNumberType DirectRouting

147. If using extension-based routing where users share a base number, append ;ext=<extension> to the number assignment, ensuring inbound SIP INVITEs carry the full number and extension string 145. Note that Cloud Voicemail provisioning occurs automatically upon licence and number assignment 143.

Verify

Place test inbound and outbound PSTN calls, perform internal calls between pilot users and CUCM extensions, verify Cloud Voicemail deposit and retrieval, and run Direct Routing self-diagnostics in the Microsoft 365 admin center 95.

Rollback

Remove the assigned phone number with Remove-CsPhoneNumberAssignment and restore the user's prior coexistence mode 147 8. Reactivate the directory number on CUCM 17.

Step 10 Provision or migrate endpoint hardware

Retire Cisco phones for Teams clients and Teams-certified devices

Do

Deploy Microsoft Teams desktop and mobile clients, Teams-certified IP phones, or Common Area Phones, all supported by Direct Routing 28. Assign Microsoft Teams Shared Device licences to shared phones and Teams Rooms Pro to conference rooms 52. Note that Common Area Phones using Direct Routing do not require Calling Plan licences 28.

Verify

Suggested check: sign in to each replacement phone or client and verify incoming and outgoing audio.

Rollback

Suggested rollback: leave existing desk phones plugged into the local switch and active on the PBX.

Convert eligible phones to MPP firmware for Teams SIP Gateway

Do

Verify that phone models appear on the Teams SIP Gateway compatibility list: 6821, 6841, 6851, 6861, 6871, 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865 and 8832 running multiplatform firmware (minimum 11.1.1MPP, approved 12-0-7MPP) 127. Exclude the 8821 and 8831, which Cisco lists as not eligible to migrate to multiplatform firmware 74. Confirm that phones run enterprise firmware 14.2.1SR1 or later before initiating conversion 76.

Cisco IP Phone 7841An original schematic of the Cisco IP Phone 7841: the handset, screen, softkeys, call and feature keys, and its four line buttons. This drawing picks out applications as number 14.12345678910111213141516
Cisco IP Phone 7841. 1 Handset. 2 Handset light strip. 3 Screen. 4 Line buttons (four: two on each side of the screen). 5 Softkeys. 6 Hold/Resume. 7 Transfer. 8 Conference. 9 Speakerphone. 10 Mute. 11 Headset. 12 Volume. 13 Contacts. 14 Applications. 15 Messages. 16 Keypad. Schematic, not to scale.

Reset each phone to factory default settings, which is required prior to onboarding on SIP Gateway 134. Enable users with Set-CsTeamsCallingPolicy -Identity <policy> -AllowSIPDevicesCalling $true, allowing up to 24 hours for policy propagation 133. Ensure users have a PSTN-enabled phone number 130. Configure DHCP option 160 with the regional provisioning URL appended with /$PSN.xml (for example, http://noam.ipp.sdg.teams.microsoft.com/$PSN.xml) 136. Allow outbound firewall access over UDP ports 49152 to 53247 and TCP port 5061 towards 52.112.0.0/14 and 52.122.0.0/15, bypassing HTTP proxies and using IPv4 135. Cisco ATA 191 Multiplatform Analog Telephone Adapter is verified for interoperability between Direct Routing and analog devices 1; WarmTransfer's reading of the sources is that ATA191-MPP and ATA192-MPP support only static location with SIP Gateway 124. Note that compatible Cisco MPP phones discover dynamic location via LLDP only 126, and SIP Gateway registered address fallback is not supported for Direct Routing 137. When assigning SIP devices to call queues, note that SIP Gateway does not publish presence, preventing presence-based queue routing 129.

Verify

Check that onboarded devices appear in Teams admin center under Teams devices > SIP devices, place a test call, and confirm paired devices remain connected (SIP Gateway automatically offboards paired devices disconnected for 30 days and unpaired devices after 14 days) 125.

Rollback

Cisco states that phones running MPP firmware 11.3.3 or later can be converted back to enterprise firmware without requiring a licence 78. Re-register the rolled-back phones to CUCM, noting factory resets during onboarding erase previous configurations 134.

Keep phones registered to CUCM for non-migrated users

Do

In CUCM, translation patterns manipulate dialled digits and reroute calls with the calling search space configured on the pattern 17, and a route pattern directs a dial string to a gateway or route list 15. Maintain existing CUCM emergency route patterns and configurations for these endpoints, as Direct Routing requires specific emergency call routing policies that do not apply to them 35.

Verify

Suggested check: verify two-way calling between a desk phone and a migrated client.

Rollback

Suggested rollback: leave existing desk phones registered to the local call manager.

Step 11 Recreate hunt groups and voice applications

Do

Convert CUCM hunt pilots to Microsoft Teams call queues, placing an auto attendant in front of each queue to manage holiday and after-hours schedules, as call queues lack native holiday and business-hour routing 153. Create a resource account for each queue and attendant, assign a Microsoft Teams Phone Resource Account licence, and assign the former hunt pilot DID to the resource account 52 154. Note that internal Teams users call the resource account directly while external PSTN callers dial the assigned DID 154. Replicate hunt group timeout and busy policies using call queue exception handling to redirect callers to people, voicemail, secondary queues, or auto attendants when queues exceed size or wait limits or have no signed-in agents 152. Note that Microsoft Media Processors are always inserted in the media path for auto attendants and call queues 65.

Verify

Suggested check: place external and internal test calls to each resource account DID, testing business-hours, after-hours, timeout redirects, and overflow thresholds.

Rollback

Unassign the DID from the resource account and repoint incoming carrier routes to the CUCM hunt pilot 154.

Step 12 Configure branch survivability

No branch survivability appliance

Do

Document WAN outage risks per branch location, noting that Direct Routing media routes through Microsoft Media Processors across the WAN by default unless media bypass is active 31.

Verify

Suggested check: confirm documented risk sign-off and mobile calling procedures for branch sites.

Rollback

Suggested rollback: retain existing branch WAN configuration.

Deploy Survivable Branch Appliances

Do

Obtain the Survivable Branch Appliance package from your SBC vendor, as Microsoft provides the SBA as distributable code embedded in vendor firmware or hosted on a separate VM 100. Enable media bypass on the SBC gateway using Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -MediaBypass $true, which keeps media local between the client and SBC 58 64 104. Open firewall ports 3443, 4444, and 8443 from SBA to Teams clients, port 5061 between SBA and SBC, UDP port 123 for NTP, and port 443 outbound to Microsoft 365, ensuring TLS 1.2 is enabled on the SBA OS 104. Configure SBA policies using Teams PowerShell cmdlets (New-CsTeamsSurvivableBranchAppliance, New-CsTeamsSurvivableBranchAppliancePolicy, and Grant-CsTeamsSurvivableBranchAppliancePolicy), as the Teams admin center does not support SBA configuration 99. Note SBA operating limits: SBA supports physical Windows desktop, macOS desktop, and Teams phone clients (excluding VMs and web clients) 98; during outages, clients can place/receive PSTN calls, hold, resume, blind transfer, and forward, but emergency location information is not shared during emergency calls 103 101. Ensure regular voice routes contain patterns matching raw emergency dial strings without a leading plus, as SBA bypasses normalization and does not support emergency call routing policies 102. If Continuous Access Evaluation is enabled in the tenant, note that SBA remains operational for approximately 30 minutes during an outage unless CAE is disabled 97.

Verify

Validate media bypass prior to branch deployment by setting up a secondary trunk with a separate FQDN and ports for staged testing 63. Suggested check: simulate a WAN failure at a branch and confirm physical desktop clients transition to SBA mode and place PSTN calls.

Rollback

Unassign SBA policies from branch users with Grant-CsTeamsSurvivableBranchAppliancePolicy -PolicyName $null and disable media bypass on the gateway with Set-CsOnlinePSTNGateway -MediaBypass $false 99 64.

Retain CUCM or SRST locally for registered devices

Do

Retain local call control for locally registered IP phones during WAN disruptions, routing calls to gateways and trunks using CUCM route patterns 15.

Verify

Suggested check: isolate branch WAN connectivity and verify that local desk phones fall back to survivable gateways and place PSTN calls.

Rollback

Suggested rollback: retain local call routing configurations on branch gateways.

Step 13 Execute migration cutover

Phased coexistence with parallel call routing

Do

Migrate user batches iteratively by assigning Teams Only mode, allocating phone numbers, and applying voice routing policies 150 147 88. Monitor Direct Routing SBC availability: Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last 3 regular one-minute intervals, demoting unresponsive SBCs from active routing 70. When MaxConcurrentSessions is set, alerting notifies the administrator at 90 percent or more of that value, and when it is not set no alerts are generated 106. Check SBC logs directly for pairing failures or rejected INVITEs (such as invalid FQDNs), because Call Analytics captures only failures that reach internal Teams components 68.

Verify

Suggested check: confirm in Call Quality Dashboard and SBC logs that inbound and outbound calls complete without gateway demotion or SIP errors.

Rollback

Per user, clear the Teams number assignment and restore the directory number and line appearance on CUCM 147 17.

Site-by-site flash cutover in scheduled maintenance windows

Do

During the scheduled cutover window, switch CUCM site route patterns to route all site number blocks across the SIP trunk to CUBE 15. Grant the online voice routing policy to all site users and assign their phone numbers 88 147. Monitor SBC logs and concurrent call capacity in real time during the cutover 106 68.

Verify

Suggested check: test the main site pilot number, selected individual DIDs, hunt group numbers, and an emergency call within the maintenance window.

Rollback

Revert CUCM route patterns to their original pre-cut partitions to return call routing to local CUCM lines 15.

Step 14 Decommission migrated CUCM resources

Do

Following post-cutover stabilization, delete migrated directory numbers, translation patterns, and device associations from CUCM 17. Maintain the CUCM-to-CUBE coexistence trunk until all tenant populations have cut over 15. If the organisation operated an integrated Skype for Business Server environment, assign TeamsOnly mode tenant-wide only after all on-premises users are migrated with Move-CsUser and Skype for Business DNS records are repointed to Microsoft 365 9. If numbers are being transitioned from Direct Routing to Microsoft Calling Plan, release them from tenant inventory using New-CsOnlineTelephoneNumberReleaseOrder 81.

Verify

Suggested check: confirm no active registrations or call traffic remain on decommissioned nodes.

Rollback

Suggested rollback: restore deleted configurations from the pre-maintenance cluster backup.

Applicability

Applies to: Microsoft certified SBC list, Microsoft Teams Phone, Cisco Unified Border Element, Microsoft Teams, Cisco Unified Communications Manager, Microsoft Teams Phone Direct Routing, Microsoft Teams emergency calling, Cisco IP Phone 8800 Series, Cisco collaboration devices, Microsoft Teams Phone Calling Plan, Microsoft Teams SIP Gateway, Microsoft Teams Phone voice applications, Microsoft Teams Phone Calling Plans, Cisco Unified Border Element (CUBE), ISI Telemanagement Solutions migration analytics, Cisco Unified Communications Manager, Cisco Webex Calling, and Cisco. Deployments: on-premises, hybrid, multi-tenant, and on-premises-unified-cm. Sources checked 2026-09-21. The end of software maintenance releases for Version 14 perpetual on-premises calling applications was 7 April 2026 155, and the last date of support is 30 April 2027 156. Cisco CUBE is certified at IOS XE Amsterdam 17.2.1r (recommended 17.6.1a; 17.3.3 for CSR 1000V; Catalyst 8000 Edge supported from 17.3.2) 13. Microsoft Direct Routing self-diagnostics are unavailable in Microsoft 365 Government, 21Vianet, or Germany clouds 95, and SIP Gateway is unavailable in DoD environments 130.

What remains uncertain

The specific Cisco IOS XE dial-peer, SIP profile, and trustpoint CLI syntax required on CUBE for Teams Direct Routing is not covered by the sources below. Migration mechanisms for Cisco Unity Connection voicemail greetings and stored messages are not covered by the sources below. Cisco Unified Contact Center Express or Enterprise migration paths are not covered by the sources below. Microsoft's certified SBC table marks Cisco CUBE as certified for non-media bypass and media bypass and marks the 911 service provider capable column as satisfied, but leaves the ELIN capable column blank 11. SIP OPTIONS pings must not exceed a frequency of one transaction every 60 seconds and must not be more or less frequent than one transaction every 180 seconds for each configured trunk for each endpoint 115.

See also

Adjacent to

  • Teams sip gatewaystub — Relevant only where the organisation wants to keep Cisco desk phones after the migration by converting them to multiplatform firmware.

Compare with

  • CUCM to Webex Calling migration — The other common destination for a CUCM estate. Cisco publishes first-party migration tooling for that path; Microsoft publishes none for this one; which is why this guide rebuilds the dial plan rather than importing it.

Depends on

  • Cisco unified border elementstub — CUBE is the Microsoft-certified SBC most CUCM estates already own; it is what terminates Direct Routing towards Microsoft and the CUCM SIP trunk towards the remaining on-premises estate.
  • Microsoft teams direct routingstub — Direct Routing is the only PSTN model that lets an organisation keep its existing carrier trunks and its CUBE estate while users move to Teams.

Migrates from

  • Cisco unified communications managerstub — The source system. No topic packet exists for CUCM yet; this guide only touches the CUCM objects a migration has to change - SIP trunks to CUBE; route patterns; translation patterns and directory numbers.

Migrates to

  • Microsoft teams phone — The target system. No topic packet exists for Teams Phone yet; the registry's Direct Routing; SIP Gateway; SBA; emergency calling and licensing claims already sit under this guide's topic id.

Referenced by

  • Microsoft teams phone — Inbound relationship: cucm-to-teams-phone migrates-to microsoft-teams-phone. Teams Phone is the target system of that migration guide.

Sources

  1. 1
    Cisco ATA 191 Multiplatform Analog Telephone Adapter is verified for interoperability between Direct Routing and analog devices, alongside AudioCodes, Oracle and Ribbon adapters and gateways.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Session Border Controllers certified for Direct Routing > Direct Routing and analog devices interoperability · Checked 2026-09-16
  2. 2
    The number of user (subscriber) numbers obtainable from Microsoft equals the total number of Domestic and/or International Calling Plan licences multiplied by 1.1 plus 10 extra numbers, pay-as-you-go licences allow only 1 number each, and these limits exclude numbers that are ported or porting to Microsoft.
    Get Microsoft Calling Plan telephone numbers for your organization · Get Microsoft Calling Plan telephone numbers for your organization > How many telephone numbers can you get? · Checked 2026-09-16
  3. 3
    New numbers are acquired through the Teams admin center Add phone numbers wizard under Voice > Phone numbers > Add > From Operator, and the Voice option only appears once at least one Enterprise E5 or E3 licence, one Phone System add-on licence, or one Audio Conferencing add-on licence is owned.
    Get Microsoft Calling Plan telephone numbers for your organization · Get Microsoft Calling Plan telephone numbers for your organization > Get new phone numbers, steps 1-4 · Checked 2026-09-16
  4. 4
    With Microsoft Teams Calling Plan, PSTN access, phone numbers, emergency screening service in the U.S. and support come from Microsoft with a 99.999% reliability Service Level Agreement.
    PSTN connectivity options · PSTN connectivity options > Microsoft Teams Calling Plan bullet · Checked 2026-09-16
  5. 5
    Cisco's Unified Border Element interoperability portal publishes three Microsoft Direct Routing documents: Direct Routing for Microsoft Phone System with CUBE and Direct Routing for Microsoft Phone System with Cisco UCM via CUBE, both labelled CUBE Release 14.4, and a multi-tenant Direct Routing with CUBE-HA guide labelled IOS-XE 17.9.1a.
    Cisco Unified Border Element (CUBE) / SIP Trunking Solutions · Interoperability portal document list, Microsoft Phone System entries · Checked 2026-09-21
  6. 6
    Cisco files the CUCM-via-CUBE Direct Routing note under the 'Cisco Unified Border Element to Third-Party IP PBX' grouping, described as notes on connecting CUBE to various non-Cisco devices using SIP or H.323, and the portal page states no certification status for these Direct Routing documents.
    Cisco Unified Border Element (CUBE) / SIP Trunking Solutions · Cisco Unified Border Element (CUBE) / SIP Trunking Solutions > Cisco Unified Border Element to Third-Party IP PBX (section intro) and the Direct Routing entries · Checked 2026-09-16
  7. 7
    Cisco's CUBE interoperability portal lists 'Direct Routing for Microsoft Phone System with Cisco Unified Communications Manager (UCM) via CUBE' and 'Direct Routing for Microsoft Phone System with Cisco Unified Border Element (CUBE)' under CUBE Release 14.4, and 'Deploying a Multi-tenant Direct Routing for Microsoft Phone System with CUBE-HA' at IOS-XE 17.9.1a under CUBE Release 14.6.
    Cisco Unified Border Element (CUBE) / SIP Trunking Solutions · Cisco Unified Border Element (CUBE) / SIP Trunking Solutions > Cisco Unified Border Element to Third-Party IP PBX > CUBE Release 14.6 and CUBE Release 14.4 groupings · Checked 2026-09-16
  8. 8
    The coexistence modes an administrator can set are Islands, Skype for Business only, Skype for Business with Teams collaboration, Skype for Business with Teams collaboration and meetings, and Teams only, and only users homed in the cloud can be given TeamsOnly mode while the other modes apply only to users homed in Skype for Business Server on-premises.
    Set your coexistence and upgrade settings · Set upgrade options for a single user in your organization, step 3 · Checked 2026-09-21
  9. 9
    TeamsOnly mode can be assigned to an entire tenant only after all on-premises users have been moved to Teams Only with Move-CsUser in the Skype for Business Server toolset and any Skype for Business DNS records have been repointed to Microsoft 365.
    Set your coexistence and upgrade settings · Set upgrade options for all users in your organization, Important callout under 'Teams only' · Checked 2026-09-21
  10. 10
    Cisco documents Cisco Unified Border Element as able to bridge enterprise and PSTN with cloud calling services such as Webex Calling and MS Teams Direct Routing, and describes CUBE as a network-to-network demarcation interface for signalling and media interworking, address and port translation, billing, security, quality of service, call admission control and bandwidth management.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Overview of Cisco Unified Border Element · Overview of Cisco Unified Border Element, capability list · Checked 2026-09-21
  11. 11
    Microsoft's table marks Cisco CUBE as certified for both non-media bypass and media bypass, and leaves the 'ELIN capable' column blank for Cisco CUBE while marking the 911 service provider capable column as satisfied.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table > Cisco rows, Media bypass and ELIN capable columns · Checked 2026-09-16
  12. 12
    Cisco Unified Border Element (CUBE) is certified for Direct Routing on ISR 1000 Series, ISR 4000 Series, CSR 1000V, ASR 1000 Series and Catalyst 8000 Edge Platforms.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Session Border Controllers certified for Direct Routing > Certified SBC vendors > Cisco rows · Checked 2026-09-16
  13. 13
    The Cisco CUBE rows are certified at IOS XE Amsterdam 17.2.1r (recommended 17.6.1a; 17.3.3 for CSR 1000V; Catalyst 8000 Edge supported from 17.3.2), and the table notes that firmware higher than documented is supported as long as the major.minor version is unchanged.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors > Cisco rows, Software version column; and the firmware-version note above the table · Checked 2026-09-16
  14. 14
    Cisco does not appear in the Microsoft page's 'Support for Local Media Optimization' vendor table, which lists AudioCodes, Ribbon, TE-SYSTEMS, Oracle, Avaya, Italtel and Enghouse Networks.inferred
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Session Border Controllers certified for Direct Routing > Support for Local Media Optimization · Checked 2026-09-16
  15. 15
    In Cisco Unified Communications Manager a route pattern directs a matching dial string to a gateway or to a route list, a route list is a prioritised list of the available paths for the call, and a route group distributes the call to gateways and trunks.
    System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing · Configure Call Routing > route pattern, route list and route group definitions · Checked 2026-09-21
  16. 16
    A Cisco Unified Communications Manager SIP trunk can be assigned up to 16 different destination addresses using IPv4 or IPv6 addressing, fully qualified domain names, or a single DNS SRV record.
  17. 17
    A Cisco Unified Communications Manager translation pattern manipulates the dialled digits first and then reroutes the call using the calling search space configured within that pattern.
    System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing · Configure Call Routing > translation pattern description · Checked 2026-09-21
  18. 18
    The Cisco Unified Communications Manager trunk configuration task flow is to configure a SIP profile, then a SIP trunk security profile carrying settings such as TLS signalling encryption and digest authentication, then the SIP trunk that applies both profiles.
    System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks · Configure Trunks > Trunk Configuration Task Flow · Checked 2026-09-21
  19. 19
    Tenant dial plans are managed with New-CsTenantDialPlan, Set-CsTenantDialPlan and Grant-CsTenantDialPlan, and the result for a given user and dialled number is checked with Get-CsEffectiveTenantDialPlan and Test-CsEffectiveTenantDialPlan.
    Create and manage dial plans · Using PowerShell > Using single cmdlets · Checked 2026-09-21
  20. 20
    Microsoft recommends that Direct Routing customers use dial plans that normalise numbers to include a plus and then remove the plus with a route-based translation rule, to avoid double normalisation.
    Translate phone numbers for Direct Routing · Route-based number translations - for outbound calls, Note · Checked 2026-09-21
  21. 21
    Teams traverses a dial plan's normalization rules from the top down and uses the first rule that matches the dialled number, so more restrictive rules must be sorted above less restrictive ones.
    Create and manage dial plans · Using the Microsoft Teams admin center > Create a dial plan, Note at step 4 · Checked 2026-09-21
  22. 22
    Where the user's effective dial plan applies no normalisation rule to the dialled number, the Teams service dial plan prepends +CC using the country or region code of the dialling user's usage location, for Calling Plans, Direct Routing and PSTN conference dial-out.
    Translate phone numbers for Direct Routing · Route-based number translations - for outbound calls, Note · Checked 2026-09-21
  23. 23
    Under Direct Routing the organisation can use any PSTN operator, with the integration achieved through a certified SBC procured, installed and managed by the customer, its integrator, or a Direct-Routing-as-a-Service provider.
    PSTN connectivity options · PSTN connectivity options > Direct Routing bullet and its sub-bullet · Checked 2026-09-16
  24. 24
    Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used, and Microsoft reserves the right to decline support cases where a non-certified device is connected.
    Plan Direct Routing · Plan Direct Routing > Support boundaries · Checked 2026-09-16
  25. 25
    Direct Routing supports SILK, G.711, G.722, G.729, and AMR-WB (non-bypass only) between Microsoft Teams and the SBC, and Microsoft does not support media re-targeting during an active Direct Routing call.
    Plan Direct Routing · Plan Direct Routing > Supported codecs (including the note following the list) · Checked 2026-09-16
  26. 26
    Direct Routing SIP signalling targets three FQDNs in priority order - sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com - resolving into 52.112.0.0/14 and 52.120.0.0/14, over SIP/TLS to destination port 5061.
    Plan Direct Routing · Plan Direct Routing > SIP signalling: FQDNs and SIP signalling ports · Checked 2026-09-16
  27. 27
    Direct Routing connects an organisation's own telephony infrastructure to Microsoft Teams Phone by using a supported, customer-provided Session Border Controller (SBC), which is the mechanism a CUCM estate would use to keep its own PSTN carrier.
    Plan Direct Routing · Plan Direct Routing > opening paragraph · Checked 2026-09-16
  28. 28
    Direct Routing supports Microsoft Teams desktop and mobile clients, Teams-certified phones and Common Area Phones, and a Calling Plan licence isn't required for Common Area Phones when Direct Routing is used.
    Plan Direct Routing · Plan Direct Routing > Supported endpoints · Checked 2026-09-16
  29. 29
    Direct Routing can be deployed alongside Microsoft Calling Plan, Operator Connect and Teams Phone Mobile in the same tenant, with a common pattern being Calling Plan or Operator Connect for PSTN calling and Direct Routing for third-party PBXs, analog devices and specialised routing.
    Plan Direct Routing · Plan Direct Routing > Direct Routing with Calling Plan and Operator Connect · Checked 2026-09-16
  30. 30
    A Direct Routing deployment requires a Microsoft-certified SBC, one or more PSTN trunks connected to the SBC, a Microsoft 365 tenant hosting Teams users homed online, one or more verified domains (not *.onmicrosoft.com), a public IP reachable by Teams, an SBC FQDN registered in the tenant, a public DNS entry for that FQDN, and a trusted public certificate.
    Plan Direct Routing · Plan Direct Routing > Infrastructure requirements · Checked 2026-09-16
  31. 31
    Media traffic on Direct Routing uses Microsoft Media Processors unless Media Bypass is enabled.
    Plan Direct Routing · Plan Direct Routing > Media traffic · Checked 2026-09-16
  32. 32
    Direct Routing isn't supported in Islands mode.
    Plan Direct Routing · Plan Direct Routing > Licensing requirements > Note · Checked 2026-09-16
  33. 33
    Microsoft's four Direct Routing configuration steps are: connect the SBC with Teams Phone and validate the connection; enable users for Direct Routing, voice and voicemail; configure call routing; and translate numbers to an alternate format.
    Configure Direct Routing · Configure Direct Routing > numbered step list · Checked 2026-09-16
  34. 34
    Teams distinguishes an emergency address (a civic street address), a place (typically a floor, building, wing or office number associated with that address), an emergency location (a civic address with an optional place, carrying a unique location ID), and a registered address (the address assigned to a user, also called the static emergency address or address of record).
    Plan and manage emergency calling · Plan and manage emergency calling > Emergency address (definitions table) · Checked 2026-09-16
  35. 35
    Emergency call routing determines how an emergency call reaches the PSAP and depends on the country's emergency calling network, the client type and the PSTN connectivity option; Direct Routing requires configuring specific emergency call routing policies, whereas with other connectivity options the carrier handles much of the routing configuration.
    Plan and manage emergency calling · Plan and manage emergency calling > Emergency call routing · Checked 2026-09-16
  36. 36
    For Direct Routing users, dynamic enablement of emergency calling or dynamic configuration of security desk notification requires both trusted IP addresses and network sites to be configured; if only dynamic locations are required, trusted IP addresses alone are enough.
    Configure dynamic emergency calling · Configure network settings, 'For Direct Routing users' list · Checked 2026-09-21
  37. 37
    For Direct Routing the organisation must either configure a connection to an Emergency Routing Service provider in the United States and Canada or configure the SBC for an Emergency Location Identification Number application.
    Configure dynamic emergency calling · Emergency calling prerequisites for Direct Routing > Set up an Emergency Routing Service provider · Checked 2026-09-21
  38. 38
    To assign an emergency location to a network identifier for dynamic emergency calling, the emergency address must contain an appropriate geo code, and Microsoft recommends creating addresses with the Teams admin center map search so they are formatted, validated and geo-coded automatically.
    Plan and manage emergency calling · Plan and manage emergency calling > Emergency address > Emergency address geo codes (including the Important note) · Checked 2026-09-16
  39. 39
    The Location Information Service returns a location by matching the client's network connectivity in the order WAP, Ethernet switch and port, Ethernet switch, then subnet, and the first match is used.
    Configure dynamic emergency calling · Plan for emergency calling, step 2 LIS match list · Checked 2026-09-21
  40. 40
    Dynamic emergency calling including security desk notification is not supported on the Teams web client, and Microsoft's remedy is to turn off the Web PSTN calling setting in a Teams calling policy assigned to web client users.
    Configure dynamic emergency calling · Supported clients, Note after the client list · Checked 2026-09-21
  41. 41
    For Direct Routing the peer PSTN gateway must be told to add location information to the outgoing emergency INVITE by setting PidfloSupported to true, either with Set-CsOnlinePSTNGateway -PidfloSupported $true or the 'SBC supports PIDF/LO for emergency calls' toggle in Teams admin center.
    Configure dynamic emergency calling · Emergency calling prerequisites for Direct Routing > Change PIDF/LO in Teams admin center and in PowerShell · Checked 2026-09-21
  42. 42
    Emergency calling policies in Teams apply when Calling Plans, Operator Connect, Teams Phone Mobile or Direct Routing is the PSTN connectivity option, and let an administrator allow end users to configure their emergency address at remote locations, configure emergency numbers, and configure who is notified when a user calls emergency services.
    Manage emergency calling policies in Microsoft Teams · Manage emergency calling policies in Microsoft Teams > intro and 'The emergency calling policy enables you to' list · Checked 2026-09-16
  43. 43
    Some changes to network settings such as a new address or network identifier can take up to four hours to propagate and become available to Teams clients.
    Configure dynamic emergency calling · Configure network settings, paragraph after the trusted IP note · Checked 2026-09-21
  44. 44
    If an emergency calling policy is assigned to a network site and to a user, and the user is at that network site, the policy assigned to the network site overrides the policy assigned to the user.
    Manage emergency calling policies in Microsoft Teams · Manage emergency calling policies in Microsoft Teams > second paragraph · Checked 2026-09-16
  45. 45
    The 933 test number validates emergency configuration for Calling Plan, Operator Connect and Teams Phone Mobile users in the United States and Canada, while Direct Routing customers in the United States should coordinate with their Emergency Routing Service provider for a test service.
    Configure dynamic emergency calling · Test emergency calling · Checked 2026-09-21
  46. 46
    A vendor page states that Cisco has announced end of life for CUCM v12.5 and v14, without giving any end-of-sale or end-of-support dates.field report
    Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide · Migrating from CUCM to Microsoft Teams? > migration drivers / lifecycle section · Checked 2026-09-16
  47. 47
    A vendor of migration analytics markets simultaneous CUCM and Teams reporting as necessary during phased migrations, which is evidence that phased coexistence between CUCM and Teams Phone is the common field pattern rather than a single cutover.field report
    Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide · Migrating from CUCM to Microsoft Teams? > phased migration / reporting sections · Checked 2026-09-16
  48. 48
    A migration-analytics vendor states that native Microsoft Teams reporting retains call history for 27 days, with a 28-day EUII policy in Call Quality Dashboard.field report
    Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide · Migrating from CUCM to Microsoft Teams? > reporting limitations section · Checked 2026-09-16
  49. 49
    Firewalls must allow Direct Routing signalling traffic to and from all Microsoft Teams IP ranges, not only the addresses returned by a DNS query for the SIP proxy FQDNs.
    Plan Direct Routing · SIP signaling: FQDNs, Important callout after the IP range list · Checked 2026-09-21
  50. 50
    All users who need their own telephone number must be licensed for the Microsoft Teams and Microsoft 365 Phone System applications; where any Microsoft 365 E5 licence is used it is not necessary to also assign the standalone Microsoft Teams Phone Standard licence.
    Teams Phone licensing · Licensing Teams Phone - for end users · Checked 2026-09-16
  51. 51
    If Microsoft provides the PSTN access and phone numbers, the user additionally requires a Microsoft Calling Plan licence; if a non-Microsoft PSTN operator is used, Microsoft requires no other licensing because the PSTN costs are incurred from that operator.
    Teams Phone licensing · Licensing Teams Phone - adding PSTN · Checked 2026-09-16
  52. 52
    Common area telephones use the Microsoft Teams Shared Device licence, Teams Rooms use Teams Room Pro, and voice applications such as auto attendants and call queues use the Microsoft Teams Phone Resource Account licence; the Phone System application is included in the shared device licences.
    Teams Phone licensing · Licensing Teams Phone - for shared devices and Licensing Teams Phone - for voice applications · Checked 2026-09-16
  53. 53
    Because a user can have multiple endpoints, support of SIP 183 is not possible on inbound bypassed calls and Direct Routing always uses 180 Ringing in that case.
    Configure Local Media Optimization for Direct Routing · Call flows > Always Bypass mode > Inbound calls and the user is in the same location as the SBC with Always Bypass · Checked 2026-09-16
  54. 54
    Local Media Optimization is configured from the same network settings used by Location-Based Routing and dynamic emergency calling: trusted IP addresses, network regions, network sites and network subnets, plus a virtual topology that assigns SBCs to sites with a mode and a proxy SBC.
    Configure Local Media Optimization for Direct Routing · Configure Local Media Optimization for Direct Routing > intro and Configure the user and the SBC sites · Checked 2026-09-16
  55. 55
    For Local Media Optimization the -MediaBypass parameter must be set to $true, and if the SBC does not have the -BypassMode parameter set then X-MS headers will not be sent.
    Configure Local Media Optimization for Direct Routing · Define the virtual network topology > notes on the Set-CsOnlinePSTNGateway parameters · Checked 2026-09-16
  56. 56
    In split-tunnel VPN scenarios where the Teams client is detected as external but can still reach the internal interface of the Direct Routing SBC, Microsoft signals the external location to the SBC, which can cause prolonged call setup and in some cases no audio on inbound PSTN calls; the page says VPN administrators must block access between remote VPN users and the SBC internal interface.
    Configure Local Media Optimization for Direct Routing · Configure the user and the SBC sites > Note on split-tunnel VPN · Checked 2026-09-16
  57. 57
    When BypassMode is defined, Direct Routing adds X-MS-UserLocation (internal or external), X-MS-MediaPath (the ordered SBC list for the media path, with the final SBC always last) and X-MS-UserSite (the tenant administrator's site string) to SIP INVITEs and re-INVITEs, and the Request-URI targets the SBC FQDN.
    Configure Local Media Optimization for Direct Routing · X-MS Headers introduced in Direct Routing on Invites and Re-Invites if BypassMode is defined (table) · Checked 2026-09-16
  58. 58
    Media bypass keeps media between the SBC and the client instead of sending it via Microsoft Teams Phone, and to configure it the SBC and the client must be in the same location or network.
    Plan for media bypass with Direct Routing · About media bypass with Direct Routing · Checked 2026-09-16
  59. 59
    For direct media between a Teams client and the SBC, UDP/SRTP is required on destination ports 50000-50019 at the SBC, whereas media to and from Microsoft Media Processors uses 3478-3481 and 49152-53247.
    Plan for media bypass with Direct Routing · Media traffic: IP and Port ranges > Requirements for direct media traffic and Requirements for using media processors · Checked 2026-09-16
  60. 60
    Media bypass is supported with standalone Teams desktop clients, Android and iOS clients and Teams Phone devices; for other endpoints that don't support media bypass, including Skype for Business 3PIP phones and WebRTC-based web clients, the call is converted to non-bypass automatically.
    Plan for media bypass with Direct Routing · Client endpoints supported with media bypass · Checked 2026-09-16
  61. 61
    Media bypass uses ICE on the Teams client and ICE Lite on the SBC, and Microsoft points readers to RFC 5245 for those protocols.
    Plan for media bypass with Direct Routing · About media bypass with Direct Routing, final paragraph · Checked 2026-09-16
  62. 62
    Teams Transport Relays have two versions - v4 requiring port range 50000 to 59999 and v6 working with 3478 to 3481 - and Microsoft recommends at least two ports per concurrent call on the SBC.
    Plan for media bypass with Direct Routing · Requirements for using Transport Relays · Checked 2026-09-16
  63. 63
    To move from non-media bypass to media bypass while confirming functionality first, Microsoft documents creating a second trunk with a different FQDN pointing at the same SBC, with different TLS SIP signalling ports, a separate Online Voice Routing policy, and that policy assigned only to identified pilot users.
    Plan for media bypass with Direct Routing · Configure separate trunks for media bypass and non-media bypass · Checked 2026-09-16
  64. 64
    Media bypass is controlled per SBC with the Set-CSOnlinePSTNGateway command and the -MediaBypass parameter set to true or false, and enabling it does not mean all media traffic stays within the corporate network.
    Plan for media bypass with Direct Routing · About media bypass with Direct Routing, second paragraph · Checked 2026-09-16
  65. 65
    Media Processors are always in the media path for non-bypassed end-user calls and always in the media path for voice applications such as Call Park, Organizational Auto Attendant and Call Queues, and never in the path for bypassed end-user calls.
    Plan for media bypass with Direct Routing · Use of Media Processors and Transport Relays · Checked 2026-09-16
  66. 66
    Media Processors are a B2BUA and can transcode (for example SILK from the Teams client to G.711 toward the SBC), while Transport Relays are not a B2BUA and never change the codec between the client and the SBC even when traffic flows via relays.
    Plan for media bypass with Direct Routing · Use of Media Processors and Transport Relays > comparison table and transcoding explanation · Checked 2026-09-16
  67. 67
    Microsoft's Direct Routing documentation set defines no import path for an existing PBX dial plan and instead has the administrator rebuild routing as tenant dial plans, PSTN usages, voice routes and trunk translation rules; the only documented import is a Skype for Business Server dial plan exported to XML and recreated with New-CsTenantDialPlan.inferred
    Create and manage dial plans · Using PowerShell > Using a PowerShell script, final script importing OPDP1 · Checked 2026-09-21
  68. 68
    Call Analytics only helps when calls reach the internal Direct Routing components and fail; for SBC pairing problems or rejected INVITEs such as a misconfigured trunk FQDN the administrator must read the SBC logs, to which Direct Routing sends a detailed description of the issue.
    Monitor Direct Routing · Monitor Call Quality Analytics dashboard and SBC logs, final paragraph · Checked 2026-09-21
  69. 69
    When two or more SBCs in one route are considered healthy and equal, Direct Routing applies a Fisher-Yates shuffle to distribute the calls between them.
    Monitor Direct Routing · Monitoring availability of Session Border Controllers ..., final paragraph · Checked 2026-09-21
  70. 70
    Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last three regular one-minute intervals, and an SBC that has not is demoted so that it is not tried first, though a demoted SBC is retried before the call fails.
    Monitor Direct Routing · Monitoring availability of Session Border Controllers using Session Initiation Protocol (SIP) options messages · Checked 2026-09-21
  71. 71
    For non-Webex Calling migrations a per-device licence is required and is node-locked to the phone MAC address, with SKUs L-CP-E2M-88XX-CNV=, L-CP-E2M-78XX-CNV=, L-CP-M2E-88XX-CNV= and L-CP-M2E-78XX-CNV= each paired with a technical-support SKU, while Webex Calling migrations through the Control Hub assistant need no ordered licence.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > licence section and Appendix B (license generation) · Checked 2026-09-16
  72. 72
    Cisco MPP firmware runs on the 6800, 7800 and 8800 Series, but only the 7800 and 8800 series have the capability to run either MPP firmware or Enterprise firmware.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > firmware migration overview / FAQ · Checked 2026-09-16
  73. 73
    Cisco's Enterprise-to-MPP conversion document describes the phones as working with approved third-party call control systems as well as Cisco Webex Calling and cites BroadWorks, BroadCloud and BroadSoft in its FAQ, and does not mention Microsoft Teams anywhere in the content read.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > body and FAQ · Checked 2026-09-16
  74. 74
    Cisco lists the 8821 and 8831 as not eligible to migrate to multiplatform firmware.
    Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform) · Eligible 8800 models section, ineligibility sentence · Checked 2026-09-21
  75. 75
    The supported conversion routes are the Cloud Upgrader at upgrade.cisco.com, the Webex Control Hub migration assistant (Webex Calling only, licences automated, phones authorised for Webex Calling only), a UCM/CUCM-based manual method that uploads transition firmware and the licence via TFTP File Management, sets the Phone Load, and applies a Transition Authorization Rule, and self-hosted web or TFTP servers.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > table of contents and migration methods sections · Checked 2026-09-16
  76. 76
    Cisco's firmware conversion guide states that a phone must run enterprise firmware 14.2.1SR1 or later before conversion to multiplatform firmware, otherwise the documented procedures may not work.
    Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform) · Conversion prerequisites, minimum firmware statement · Checked 2026-09-21
  77. 77
    Cisco states that MPP phone firmware does not work and is not supported on Cisco Unified Communications Manager.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > FAQ · Checked 2026-09-16
  78. 78
    Cisco states that phones converted to multiplatform firmware 11.3.3 or later can be migrated back to enterprise firmware without needing a licence.
    Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform) · Migration back to Enterprise firmware section · Checked 2026-09-21
  79. 79
    Phones converted from Enterprise to MPP firmware can be migrated back to Enterprise firmware without needing a licence.
    Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware · Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > licence section · Checked 2026-09-16
  80. 80
    No Microsoft Learn document specific to migrating from Cisco Unified Communications Manager to Teams Phone was located in this run; Microsoft's migration and voice planning content is expressed in terms of PSTN connectivity models, Direct Routing components and device compatibility rather than in terms of replacing a named competitor PBX.inferred
    Plan Direct Routing · Plan Direct Routing > Why choose Direct Routing? (the page's stated fits, none of which name a vendor PBX) · Checked 2026-09-16
  81. 81
    When Direct Routing numbers are later ported to another PSTN connectivity option they must first be unassigned and then released from Microsoft's inventory with New-CsOnlineTelephoneNumberReleaseOrder before the port event.
    Enable users for Direct Routing · Upload Direct Routing numbers to your tenant > Order history, closing Note · Checked 2026-09-21
  82. 82
    Microsoft Calling Plan, Operator Connect and Direct Routing support user phone numbers, Audio Conferencing numbers and voice application numbers such as auto attendants and call queues, while Teams Phone Mobile supports user phone numbers only and does not support Audio Conferencing or voice application numbers.
    PSTN connectivity options · PSTN connectivity options > Note following the four bullets · Checked 2026-09-16
  83. 83
    The billing telephone number given on a port request must match what the current service provider has on file and any account freeze must be removed, otherwise the port request is rejected after submission.
    Transfer phone numbers to Microsoft Teams · Porting wizard - New (U.S. & Canada) > Billing telephone number (BTN) · Checked 2026-09-21
  84. 84
    Microsoft acknowledges confirmation of a submitted port request within 72 business hours, and order status is tracked in Teams admin center under Voice > Phone numbers > Order history.
    Transfer phone numbers to Microsoft Teams · Porting wizard - New (U.S. & Canada) > Confirmation · Checked 2026-09-21
  85. 85
    When numbers are ported into Calling Plans from Direct Routing or Operator Connect, preassignment is not allowed: in the United States and Canada the existing assignment can be maintained provided a Calling Plan licence and emergency location are in place before port completion, and outside the United States and Canada the numbers transfer in unassigned.
    Transfer phone numbers to Microsoft Teams · What's the status of your port orders? table, Approved (FOCAccepted) row · Checked 2026-09-21
  86. 86
    Teams Phone has four PSTN connectivity models - Microsoft Teams Calling Plan, Operator Connect, Teams Phone Mobile and Direct Routing - and an organisation can equip a tenant with as many of them as it wants and mix them per user population.
    PSTN connectivity options · PSTN connectivity options > 'The highlights of the four PSTN connectivity models for Teams are as follows' · Checked 2026-09-16
  87. 87
    A PSTN solution is separate from a Teams Phone licence: the PSTN solution provides the tenant with phone numbers and PSTN access to domestic, international and emergency calling, while the Teams Phone licence entitles a user to enhanced calling capabilities in the tenant and access to that PSTN solution.
    What is Teams Phone · What is Teams Phone > Note · Checked 2026-09-16
  88. 88
    The PowerShell chain for Direct Routing call routing is Set-CsOnlinePstnUsage to create a usage, New-CsOnlineVoiceRoute with -NumberPattern, -OnlinePstnGatewayList, -Priority and -OnlinePstnUsages, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy to assign it to a user.
    Configure call routing for Direct Routing · Example 1: Configuration steps > Using PowerShell, steps 1 to 4 · Checked 2026-09-21
  89. 89
    If a called number contains an extension the voice route number pattern is applied only to the number without the extension.
    Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 2 · Checked 2026-09-21
  90. 90
    Direct Routing call routing is built from four elements: an online voice routing policy that contains PSTN usages, PSTN usages that contain voice routes, voice routes that pair a number pattern with a set of online PSTN gateways, and the online PSTN gateway that points at an SBC.
    Configure call routing for Direct Routing · Call routing overview, element list · Checked 2026-09-21
  91. 91
    If the global (Org-wide default) online voice routing policy is configured and applied, every voice-enabled user in the organisation inherits it, which can send Calling Plan and Operator Connect users' PSTN calls to a Direct Routing trunk inadvertently.
    Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 1 · Checked 2026-09-21
  92. 92
    When an incoming PSTN call is forwarded or transferred and the ingress SBC is also a potential egress SBC, its priority value is ignored and it is prioritised above the other SBCs.
    Configure call routing for Direct Routing · Example 1: Voice routing with one PSTN usage, Note after the three-route summary table · Checked 2026-09-21
  93. 93
    For a user with only a Teams Phone licence, a call whose dialled number matches none of the administrator-created voice route patterns is dropped; only a user who also holds a Microsoft Calling Plan licence falls back to the Calling Plan route automatically.
    Configure call routing for Direct Routing · Example 1: Voice routing with one PSTN usage, Note after the third-route diagram · Checked 2026-09-21
  94. 94
    Voice routes are tried in priority order but the SBCs listed within a single route are tried in random order.
    Configure call routing for Direct Routing · Example 1: Voice routing with one PSTN usage, sentence after Call Flow 2 · Checked 2026-09-21
  95. 95
    Microsoft 365 admins can run a tenant self-diagnostics test that verifies a user is correctly configured for Direct Routing, and this feature is not available for Microsoft 365 Government, 21Vianet or Germany.
    Configure call routing for Direct Routing · Run a Self-diagnostics tool · Checked 2026-09-21
  96. 96
    The order of PSTN usages inside a voice routing policy is critical because usages are applied in order and if a match is found in the first usage the later usages are never evaluated; the order is changed with Set-CsOnlineVoiceRoutingPolicy.
    Configure call routing for Direct Routing · Example 2: Voice routing with multiple PSTN usages, Note after the routing table · Checked 2026-09-21
  97. 97
    If the tenant uses Continuous Access Evaluation tokens, the SBA is operational only for about 30 minutes because of the nature of continuous access evaluation, and an alternative is to disable CAE for the tenant.
    Survivable Branch Appliance for Direct Routing · Known issues and considerations > Continuous Access Evaluation bullet · Checked 2026-09-16
  98. 98
    SBA is supported on Teams Windows desktop, Teams macOS desktop and Teams Phones, and SBA mode activates only on desktop clients on a physical machine - VMs and web clients are not supported.
    Survivable Branch Appliance for Direct Routing · Supported Teams clients and How it works > SBA mode activation paragraph · Checked 2026-09-16
  99. 99
    All Direct Routing SBA configuration is done with Teams PowerShell cmdlets - New-CsTeamsSurvivableBranchAppliance, New-CsTeamsSurvivableBranchAppliancePolicy, Set-CsTeamsSurvivableBranchAppliancePolicy and Grant-CsTeamsSurvivableBranchAppliancePolicy - plus an application registered in Microsoft Entra ID, and the Teams admin center does not yet support the feature.
    Survivable Branch Appliance for Direct Routing · How it works > Configuration and its subsections; Register an application for the SBA with Microsoft Entra ID · Checked 2026-09-16
  100. 100
    The Survivable Branch Appliance is distributable code provided by Microsoft to SBC vendors, who embed it in firmware or distribute it separately to run on a separate VM or hardware.
    Survivable Branch Appliance for Direct Routing · Direct Routing SBA > Prerequisites, first paragraph · Checked 2026-09-16
  101. 101
    In SBA mode, sharing location information during an emergency call is not supported: users can still make the emergency call but location information will not be shared, and the only UI indicator that the client has switched to Appliance mode is a banner.
    Survivable Branch Appliance for Direct Routing · Known issues and considerations > In SBA mode, the following user actions aren't supported · Checked 2026-09-16
  102. 102
    SBA does not support Emergency Call Routing Policies; EMER dial strings bypass normalization and are always sent without a leading plus, so if the customer has no pattern in their regular voice routing policy matching the EMER dial strings, emergency calls fail via SBA.
    Survivable Branch Appliance for Direct Routing · Known issues and considerations > In SBA mode, the following user actions aren't supported · Checked 2026-09-16
  103. 103
    While offline in SBA mode, a Teams client can make and receive PSTN calls through the local SBA and SBC, hold and resume, blind transfer, forward calls to a single number or Teams user, redirect an incoming PSTN call to a call queue or auto attendant number, fall back to PSTN when a VoIP call cannot be initiated, and make VoIP calls between two users registered behind the same SBA.
    Survivable Branch Appliance for Direct Routing · How it works > When the Microsoft Teams client is in offline mode, the following calling-related functionality is available · Checked 2026-09-16
  104. 104
    SBA prerequisites include the SBC being configured for Media Bypass, TLS 1.2 enabled on the SBA VM OS, and firewall openings for ports 3443, 4444 and 8443 (SBA server to Teams client), port 5061 (SBA server to SBC), UDP 123 for NTP and port 443 for Microsoft 365.
    Survivable Branch Appliance for Direct Routing · Direct Routing SBA > Prerequisites, bullet list · Checked 2026-09-16
  105. 105
    Microsoft certifies and supports three emergency services providers for Direct Routing - Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service and Inteliquent - and may reject support cases if a non-certified provider is used.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table footnote '*' - 911 service providers · Checked 2026-09-16
  106. 106
    When MaxConcurrentSessions is set the alerting system notifies the administrator at 90 percent or more of that value, and when it is not set no alerts are generated although the monitoring system still reports concurrent sessions every 24 hours.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, 'Concurrent call capacity' row · Checked 2026-09-21
  107. 107
    The SBC certificate should carry the SBC FQDN as Common Name or Subject Alternative Name, be signed by a Certificate Authority in the Microsoft Trusted Root Program and include the Server Authentication EKU, and wildcard certificates are supported when they comply with RFC 2818.
    Plan Direct Routing · Public trusted certificate for the SBC · Checked 2026-09-21
  108. 108
    Besides the domain being registered in the tenant, a user with that domain and an assigned E3 or E5 licence must exist, and the domain's configured authentication type must be Managed, otherwise pairing fails with a domain-not-configured error.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, second and third bullets · Checked 2026-09-21
  109. 109
    The trunk failover defaults are response codes 408, 503 and 504 and a FailoverTimeSeconds of 10 seconds, after which an unanswered outbound call is routed to the next available trunk or dropped if none exists.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, 'Failover response codes' and 'Failover times (seconds)' rows · Checked 2026-09-21
  110. 110
    ForwardCallHistory and ForwardPai both default to False; turning on call history makes Microsoft 365 send History-Info and Referred-By headers, and turning on PAI also sends the Privacy:ID header.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, 'Forward call history' and 'Forward P-Asserted-identity (PAI) header' rows · Checked 2026-09-21
  111. 111
    An SBC can only be paired if the domain portion of its FQDN matches a domain registered in the tenant, and *.onmicrosoft.com domain names are not supported for the SBC FQDN.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, second bullet · Checked 2026-09-21
  112. 112
    New-CsOnlinePSTNGateway has an IPAddressVersion option of IPv4 or IPv6, and when IPv6 is set the SBC must use IPv6 for both signalling and media, with media bypass unsupported and mixed IPv6/IPv4 SIP and media unsupported.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, IPAddressVersion bullet · Checked 2026-09-21
  113. 113
    The certified SBC page repeats that media re-targeting isn't supported: if the SBC sends a new media IP during a Direct Routing call it is negotiated in signalling but Teams never sends media to the new address.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Session Border Controllers certified for Direct Routing > final Note · Checked 2026-09-16
  114. 114
    The certified SBC page states that Microsoft is not accepting new nominations for SBC certification until further notice.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Session Border Controllers certified for Direct Routing > sentence below the intro · Checked 2026-09-16
  115. 115
    SIP OPTIONS pings must not exceed a frequency of one transaction every 60 seconds and must not be more or less frequent than one transaction every 180 seconds for each configured trunk for each endpoint.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, SIP OPTIONS bullet · Checked 2026-09-21
  116. 116
    An SBC is paired to Direct Routing with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true as the minimum parameters.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant, first code block · Checked 2026-09-21
  117. 117
    SendSIPOptions defaults to True and Microsoft highly recommends leaving it on, because when it is off the SBC is excluded from the Monitoring and Alert system.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, 'Send SIP options' row · Checked 2026-09-21
  118. 118
    Multiple IP addresses mapped to the same FQDN on the SBC side are not supported for Direct Routing.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, fourth bullet · Checked 2026-09-21
  119. 119
    An SBC can be connected either in the Microsoft Teams admin center or with PowerShell, but for GCC High and DoD clouds PowerShell must be used because the admin center option is not available.
    Connect your Session Border Controller (SBC) to Direct Routing · Introduction, Note immediately before 'Use the Microsoft Teams admin center' · Checked 2026-09-21
  120. 120
    Microsoft forces TLS 1.2 on the Direct Routing SIP interface and the SBC must be able to connect with one of four ECDHE-RSA cipher suites using AES 128 or 256 in GCM or CBC mode.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, TLS bullet · Checked 2026-09-21
  121. 121
    Microsoft requires that Direct Routing issues be raised with the SBC vendor's customer support first, with the vendor escalating to Microsoft through internal channels, and customers must present an SBC vendor investigation report when opening a Microsoft support request.
    Configure Direct Routing · Configure Direct Routing > Support Boundaries · Checked 2026-09-16
  122. 122
    Pairing is verified by running Get-CsOnlinePSTNGateway and confirming the SBC appears with Enabled set to True, and by confirming in the SBC management interface that outgoing OPTIONS receive 200 OK and that the SBC answers incoming OPTIONS from Direct Routing with 200 OK.
    Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection > Check whether the SBC is on the list of paired SBCs; Validate SIP options · Checked 2026-09-21
  123. 123
    Microsoft directs the SBC to the nearest healthy datacentre and redirects to the secondary and then tertiary region if the primary is unavailable, with no manual administrator intervention required.
    Plan Direct Routing · SIP signaling failover · Checked 2026-09-21
  124. 124
    Cisco ATA191-MPP and ATA192-MPP carry footnote marker 3 in the compatible devices table, whose definition is that the device supports only static location with SIP Gateway.inferred
    Plan SIP Gateway · Compatible devices table > ATA191-MPP and ATA192-MPP rows, Remarks/footnote column; footnote 3 definition · Checked 2026-09-16
  125. 125
    SIP Gateway automatically offboards stale devices provisioned for a tenant: paired devices not connected for 30 days, and unpaired devices after 14 days; an offboarded device can be onboarded again after a factory reset.
    Plan SIP Gateway · Benefits of SIP Gateway > Off board stale devices · Checked 2026-09-16
  126. 126
    Compatible Cisco SIP IP phones support dynamic location discovery over LLDP only, and the page's footnote markers show the Cisco MPP phones and the ATA191/192-MPP as supporting dynamic location discovery through LLDP.
    Plan SIP Gateway · Plan SIP Gateway > notes under the Compatible devices table, and the ^1^/^2^/^3^ footnote definitions · Checked 2026-09-16
  127. 127
    For Cisco, devices running enterprise firmware must be converted to multiplatform firmware, and the compatible table lists 6821, 6841, 6851, 6861, 6871, 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865 and 8832 with minimum 11.1.1MPP and approved 12-0-7MPP, ATA191-MPP and ATA192-MPP at minimum 11.2.2MPP and approved 11-3-1MPP, and 8875 plus the 9841/9851/9861/9871 at PhoneOS 3.3.1.
    Plan SIP Gateway · Plan SIP Gateway > Compatible devices > Cisco rows · Checked 2026-09-16
  128. 128
    SIP Gateway lets an organisation use any compatible SIP device with Microsoft Teams, including Skype for Business IP phones with standard SIP firmware, Cisco IP phones with multiplatform SIP firmware, and SIP devices from Poly, Yealink and AudioCodes.
    Plan SIP Gateway · Plan SIP Gateway > opening paragraph · Checked 2026-09-16
  129. 129
    Customers can use SIP devices as call queue agents with restrictions, for instance SIP Gateway does not publish presence for devices so presence-based routing is not supported.
    Plan SIP Gateway · Benefits of SIP Gateway > Call Queues and voice apps support · Checked 2026-09-16
  130. 130
    Teams users must have a phone number with PSTN calling enabled to use SIP Gateway, and SIP Gateway is not yet available for DoD.
    Plan SIP Gateway · Plan SIP Gateway > Requirements to use SIP Gateway and its following Note · Checked 2026-09-16
  131. 131
    Direct Routing SIP/TLS signalling from the SBC to the Microsoft SIP proxy uses destination port 5061, while traffic from the Microsoft SIP proxy to the SBC uses the port configured on the SBC.
    Plan Direct Routing · SIP signaling ports table · Checked 2026-09-21
  132. 132
    Bulk sign-in of SIP devices works in batches of up to 100 devices with at most three concurrent batches per region, requires the site public IP to have been a trusted IP for at least 24 hours, the tenant ID in the provisioning URL, Teams PowerShell 5.6.0 or later, accounts without MFA that hold a phone number, the CommonAreaPhone policy and AllowSIPDevicesCalling.
    Configure SIP Gateway · Bulk sign in > Bulk sign in prerequisites · Checked 2026-09-21
  133. 133
    SIP Gateway is enabled for users through a Teams calling policy, either with the 'SIP devices can be used for calls' setting in Teams admin center or Set-CsTeamsCallingPolicy -AllowSIPDevicesCalling True, the default being False, and policy propagation may take up to 24 hours.
    Configure SIP Gateway · Enable SIP Gateway for the users in your organization > By using PowerShell · Checked 2026-09-21
  134. 134
    Every SIP device must be reset to factory default settings before it is used with SIP Gateway, and only compatible SIP devices can be onboarded.
    Configure SIP Gateway · Before you can configure SIP Gateway, do the following, first bullet · Checked 2026-09-21
  135. 135
    SIP Gateway requires outbound-only firewall openings of UDP ports 49152 to 53247 and TCP port 5061 towards IP ranges 52.112.0.0/14 and 52.122.0.0/15, the devices must not sit behind an HTTP proxy, and SIP Gateway supports IPv4 only.
    Configure SIP Gateway · Before you can configure SIP Gateway, do the following; and Microsoft Teams and IPv6 · Checked 2026-09-21
  136. 136
    SIP Gateway provisioning server URLs are regional - emea.ipp.sdg.teams.microsoft.com, noam.ipp.sdg.teams.microsoft.com and apac.ipp.sdg.teams.microsoft.com - and for Cisco devices the URL must have /$PSN.xml appended and is delivered with DHCP option 160.
    Configure SIP Gateway · Set the SIP Gateway provisioning server URL > Using DHCP, and the Note following it · Checked 2026-09-21
  137. 137
    SIP Gateway falls back to emergency calling based on registered addresses for devices that do not share location attributes, and registered addresses are not currently supported for Direct Routing scenarios.
    Configure SIP Gateway · Emergency calling · Checked 2026-09-21
  138. 138
    Teams Phone is Microsoft's technology for enabling call control and Private Branch Exchange (PBX) capabilities in the Microsoft 365 cloud, and Microsoft states it allows replacing an existing PBX system.
    What is Teams Phone · What is Teams Phone > opening paragraph and 'Teams Phone allows you to replace your existing PBX system...' · Checked 2026-09-16
  139. 139
    Translation rules are created with New-CsTeamsTranslationRule and attached to a gateway with New-CsOnlinePSTNGateway or Set-CsOnlinePSTNGateway through the InboundTeamsNumberTranslationRules, InboundPSTNNumberTranslationRules, OutboundTeamsNumberTranslationRules and OutboundPSTNNumberTranslationRules parameters.
    Translate phone numbers for Direct Routing · Considerations > Configuring translation rules with PowerShell · Checked 2026-09-21
  140. 140
    Inbound Direct Routing calls are matched to a Teams user or resource account by Reverse Number Lookup on the dialled number-string, so where the SBC passes through a format that does not match the assigned number-string an inbound translation rule on the gateway is needed.
    Translate phone numbers for Direct Routing · Route-based number translations - for inbound calls · Checked 2026-09-21
  141. 141
    The maximum total number of translation rules is 400, the maximum parameter-name length is 100 symbols, the maximum pattern length is 1024 symbols and the maximum translation length is 256 symbols.
    Translate phone numbers for Direct Routing · Considerations, Note listing the maximums · Checked 2026-09-21
  142. 142
    Number translation rules are applied at the SBC level, multiple rules can be assigned to one SBC and they are applied in the order in which they appear when listed in PowerShell.
    Translate phone numbers for Direct Routing · Considerations, first paragraph · Checked 2026-09-21
  143. 143
    Cloud Voicemail configuration for a Direct Routing user is automatic and requires no other configuration once the licence and number are in place.
    Enable users for Direct Routing · Configure the phone number and enable enterprise voice, opening paragraph · Checked 2026-09-21
  144. 145
    Phone numbers can be configured with extensions so several users share one base number, and for the lookup to succeed the INVITE must contain the full number with the extension, for example sip:+14255388701;ext=1001.
    Enable users for Direct Routing · Configure the phone number and enable enterprise voice > Use PowerShell, paragraph after the extension examples · Checked 2026-09-21
  145. 146
    Direct Routing requires the user to be homed online, which is checked by confirming RegistrarPool has a value in the infra.lync.com domain; where OnPremLineUri is populated the number was assigned on-premises and must be cleared with Set-CsUser -LineUri $null in the Skype for Business Management Shell and synchronised before the number is configured online.
    Enable users for Direct Routing · Ensure that the user is homed online · Checked 2026-09-21
  146. 147
    A Direct Routing number is assigned with Set-CsPhoneNumberAssignment using -PhoneNumber and -PhoneNumberType DirectRouting, and that command automatically enables the user for Enterprise Voice.
    Enable users for Direct Routing · Configure the phone number and enable enterprise voice > Use PowerShell, second bullet · Checked 2026-09-21
  147. 148
    Uploading Direct Routing numbers into Microsoft's telephone number management inventory is optional, and assigning a number to a user automatically uploads it if it is not already there.
    Enable users for Direct Routing · Upload Direct Routing numbers to your tenant, introductory paragraphs · Checked 2026-09-21
  148. 149
    Direct Routing numbers are uploaded in bulk with New-CsOnlineDirectRoutingTelephoneNumberUploadOrder using -FileContent, each request supports up to 10,000 telephone numbers, and the upload is asynchronous.
    Enable users for Direct Routing · Upload Direct Routing numbers to your tenant > Use PowerShell · Checked 2026-09-21
  149. 150
    Direct Routing requires users to be in Teams Only mode so that incoming calls land in the Teams client, which is done by assigning the UpgradeToTeams instance of TeamsUpgradePolicy.
    Enable users for Direct Routing · Assign Teams Only mode to users to ensure calls land in Microsoft Teams · Checked 2026-09-21
  150. 151
    Attaching opaque=app:voicemail to the Request-URI sends a Direct Routing call straight to the user's voicemail without ringing the Teams client.
    Enable users for Direct Routing · Configure sending calls directly to voicemail · Checked 2026-09-21
  151. 152
    Call queue exception handling can redirect calls to people, voicemail, other call queues or auto attendants when no agents are signed in, when the number of waiting callers exceeds a configured limit, or when a caller's wait time exceeds a configured limit.
    Planning - Overview of voice applications · Call Queue, exception handling list · Checked 2026-09-21
  152. 153
    Call queues do not provide separate call routing for off hours and holidays, and Microsoft recommends using an auto attendant in front of the queue to direct calls even where the queue is staffed around the clock.
    Planning - Overview of voice applications · Call Queue, closing paragraph · Checked 2026-09-21
  153. 154
    Internal Teams callers reach an auto attendant or call queue by calling its resource account, while external callers reach it by dialling the phone number assigned to that resource account.
    Planning - Overview of voice applications · Auto Attendant, final paragraph; Call Queue, final paragraph · Checked 2026-09-21
  154. 155
    The end of software maintenance releases for Version 14 perpetual on-premises calling applications was 7 April 2026, meaning Cisco may no longer issue maintenance or bug-fix builds for that release.
  155. 156
    The last date of support for Version 14 perpetual on-premises calling applications is 30 April 2027, after which Cisco states all support services are unavailable and the product is obsolete.

Documents

tier 2 current vendor documentation

Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform)

Cisco · accessed 2026-09-21

tier 2 current vendor documentation

Cisco Unified Border Element (CUBE) / SIP Trunking Solutions

Cisco · accessed 2026-09-16

tier 2 current vendor documentation

Configure call routing for Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

Configure Direct Routing

Microsoft · 2026-03-16 · accessed 2026-09-16

tier 2 current vendor documentation

Configure dynamic emergency calling

Microsoft · 2026-06-15 · accessed 2026-09-21

tier 2 current vendor documentation

Configure Local Media Optimization for Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-16

tier 2 current vendor documentation

Configure SIP Gateway

Microsoft · 2024-08-08 · accessed 2026-09-21

tier 2 current vendor documentation

Connect your Session Border Controller (SBC) to Direct Routing

Microsoft · 2026-04-26 · accessed 2026-09-21

tier 2 current vendor documentation

Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware

Cisco · 2024-12-21 · accessed 2026-09-16

tier 2 current vendor documentation

Create and manage dial plans

Microsoft · 2025-04-25 · accessed 2026-09-21

tier 2 current vendor documentation

Enable users for Direct Routing

Microsoft · 2026-08-21 · accessed 2026-09-21

tier 2 current vendor documentation

Get Microsoft Calling Plan telephone numbers for your organization

Microsoft · 2026-03-11 · accessed 2026-09-16

tier 2 current vendor documentation

Manage emergency calling policies in Microsoft Teams

Microsoft (Microsoft Learn) · 2026-04-30 · accessed 2026-09-06

tier 2 current vendor documentation

Monitor Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

Plan and manage emergency calling

Microsoft · 2026-03-23 · accessed 2026-09-16

tier 2 current vendor documentation

Plan Direct Routing

Microsoft (Microsoft Learn) · 2026-08-21 · accessed 2026-09-06

tier 2 current vendor documentation

Plan for media bypass with Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-16

tier 2 current vendor documentation

Plan SIP Gateway

Microsoft · 2025-02-28 · accessed 2026-09-16

tier 2 current vendor documentation

Planning - Overview of voice applications

Microsoft · 2026-08-31 · accessed 2026-09-21

tier 2 current vendor documentation

PSTN connectivity options

Microsoft (Microsoft Learn) · 2026-08-06 · accessed 2026-09-06

tier 2 current vendor documentation

Session Border Controllers certified for Direct Routing - Microsoft Teams

Microsoft · 2026-05-27 · accessed 2026-09-14

tier 2 current vendor documentation

Set your coexistence and upgrade settings

Microsoft · 2026-02-04 · accessed 2026-09-21

tier 2 current vendor documentation

Survivable Branch Appliance for Direct Routing

Microsoft (Microsoft Learn) · 2026-04-27 · accessed 2026-09-06

tier 2 current vendor documentation

Teams Phone licensing

Microsoft · 2026-04-28 · accessed 2026-09-16

tier 2 current vendor documentation

Transfer phone numbers to Microsoft Teams

Microsoft · 2026-05-28 · accessed 2026-09-21

tier 2 current vendor documentation

Translate phone numbers for Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

What is Teams Phone

Microsoft (Microsoft Learn) · 2026-03-03 · accessed 2026-09-06

tier 6 community and field reports

Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide

ISI Telemanagement Solutions, LLC · accessed 2026-09-16

Cite this page

APA

WarmTransfer. (2026, September 21). CUCM to Teams Phone migration. WarmTransfer. https://warmtransfer.net/guides/cucm-to-teams-phone

BibTeX

@misc{warmtransfer-cucm-to-teams-phone,
  title  = {CUCM to Teams Phone migration},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cucm-to-teams-phone},
  note   = {Verified 2026-09-21}
}