# CUCM to Teams Phone migration

Systems: Cisco Unified Communications Manager to Microsoft Teams Phone

For Voice engineers and unified-communications administrators migrating telephony from CUCM to Microsoft Teams Phone.

Canonical: https://warmtransfer.net/guides/cucm-to-teams-phone

Last verified: 2026-09-21

Microsoft positions [Microsoft Teams Phone](https://warmtransfer.net/knowledge/microsoft-teams-phone) as a cloud private branch exchange technology able to replace an existing PBX system[^138]. A Teams Phone licence and a public switched telephone network solution are managed separately: the licence supplies call control while the PSTN solution delivers numbers and dial tone[^87].

## Before you start

- Confirm that your tenant contains the required licences: Microsoft Teams and Microsoft 365 Phone System for all voice users (included with any Microsoft 365 E5 licence), separate Calling Plan licences if Microsoft supplies the PSTN access, Microsoft Teams Shared Device licences for shared hardware, and Microsoft Teams Phone Resource Account licences for auto attendants and queues[^50][^51][^52].
- WarmTransfer's reading of the sources is that Microsoft documents no automated conversion tool for importing a dial plan from [Cisco Unified Communications Manager](https://warmtransfer.net/knowledge/cisco-unified-communications-manager), meaning routing components, tenant dial plans, PSTN usages, voice routes, and translation rules must be planned and rebuilt manually[^67].
- In CUCM, a route pattern directs a matching dial string to a gateway or route list, a route list prioritises paths, and a route group distributes calls to gateways and trunks[^15].

## What changes by situation

- How do migrated users reach the PSTN? Keep carrier trunks using Cisco CUBE as the SBC; Keep carrier trunks on a non-Cisco certified SBC; Acquire PSTN access from Microsoft Calling Plan; Mix Direct Routing with Calling Plan across populations.
- How will user populations cut over? Phased coexistence with parallel call routing; Site-by-site flash cutover in scheduled maintenance windows.
- What is the plan for Cisco IP desk phones? Retire Cisco phones for Teams clients and Teams-certified devices; Convert eligible phones to MPP firmware for Teams SIP Gateway; Keep phones registered to CUCM for non-migrated users.
- How will emergency calls be routed? Certified Emergency Routing Service provider; SBC ELIN application; Microsoft-managed emergency routing.
- What survivability mechanism protects branch calling during cloud outages? No branch survivability appliance; Deploy Survivable Branch Appliances; Retain CUCM or SRST locally for registered devices.

## Step 1: Validate PSTN architecture and prerequisites

**Keep carrier trunks using Cisco CUBE as the SBC**

### Do
Review the session border controller hardware against supported platforms: [Cisco Unified Border Element](https://warmtransfer.net/knowledge/cisco-unified-border-element) is certified for [Microsoft Teams Direct Routing](https://warmtransfer.net/knowledge/microsoft-teams-direct-routing) on ISR 1000 Series, ISR 4000 Series, CSR 1000V, ASR 1000 Series, and Catalyst 8000 Edge Platforms[^12]. Verify that the CUBE firmware runs at least IOS XE Amsterdam 17.2.1r (17.6.1a recommended; 17.3.3 for CSR 1000V; 17.3.2 upwards for Catalyst 8000 Edge), noting that Microsoft supports higher versions as long as the major.minor release remains unchanged[^13]. Ensure the deployment meets all Direct Routing infrastructure prerequisites: certified SBC, connected PSTN trunks, a tenant hosting online-homed Teams users, a registered custom domain not ending in `*.onmicrosoft.com`, public IP, public DNS record, and a trusted public certificate[^30]. WarmTransfer's reading of the sources is that Cisco is not listed in Microsoft's certified vendor table for Local Media Optimization[^14].

### Verify
Suggested check: review the running configuration of each border element to confirm platform model and release match certification lists.

### Rollback
Suggested rollback: retain existing trunks and abandon deployment.

**Keep carrier trunks on a non-Cisco certified SBC**

### Do
Select an SBC model and firmware version from Microsoft's certified list, noting that Microsoft supports Direct Routing only on certified SBCs, reserves the right to decline cases involving non-certified hardware, and is not accepting new certification nominations until further notice[^24][^114]. Verify the infrastructure prerequisites: certified SBC, PSTN trunks, online-homed users, registered custom domain, public IP, public DNS, and trusted certificate[^30]. Establish support channels with the SBC vendor, as Microsoft requires Direct Routing support incidents to be submitted to the SBC vendor first and accompanied by an investigation report[^121].

### Verify
Suggested check: verify that the chosen SBC make and firmware version appear on the certified Direct Routing list.

### Rollback
Suggested rollback: leave routing directed to the existing call control system.

**Acquire PSTN access from Microsoft Calling Plan**

### Do
Confirm Microsoft Teams Calling Plan availability in the required operational regions, noting that Calling Plan bundles PSTN access, numbers, technical support, and US emergency screening under a 99.999% reliability SLA[^4]. Assign Calling Plan licences to users who require outbound PSTN dialling, alongside Teams Phone licences[^51]. Note that Calling Plan supports subscriber numbers, Audio Conferencing numbers, and voice application numbers for call queues and auto attendants[^82].

### Verify
Suggested check: inspect licence assignment in admin center for all designated pilot users.

### Rollback
Suggested rollback: remove assigned Calling Plan licences in admin center.

**Mix Direct Routing with Calling Plan across populations**

### Do
Designate user populations and functions across connectivity options, using Direct Routing for legacy PBX interop, analog devices, or specialized routing, and Calling Plan for standard users[^29]. Note that Calling Plan, Operator Connect, and Direct Routing support subscriber, conferencing, and application numbers, while Teams Phone Mobile supports only user phone numbers[^82]. Licence shared hardware with Microsoft Teams Shared Device licences, meeting spaces with Teams Rooms Pro, and voice applications with Microsoft Teams Phone Resource Account licences[^52].

### Verify
Suggested check: check user licensing and device SKU mapping across each designated migration group.

### Rollback
Suggested rollback: unassign newly added user licences and re-register analog lines to the PBX.

## Step 2: Inventory CUCM dial patterns and extensions

### Do
In CUCM, a route pattern directs a matching dial string to a gateway or route list, a route list prioritises paths, and a route group distributes calls to gateways and trunks[^15]. Note that CUCM translation patterns rewrite digits and route calls using their internal calling search space[^17]. Inventory real DIDs versus non-routable internal extensions, noting that Teams routes inbound calls to users by performing Reverse Number Lookup on the received dialled number-string[^140].

### Verify
Suggested check: verify that all exported directory numbers are mapped to a target destination or tagged to remain on-premises.

### Rollback
Suggested rollback: retain exported inventory files as archival reference.

## Step 3: Configure network perimeter, domains, and certificates

**Keep carrier trunks using Cisco CUBE as the SBC**

### Do
Register the FQDN domain of the CUBE in the tenant, ensuring the domain does not use `*.onmicrosoft.com`[^111]. Verify that a user with an assigned E3 or E5 licence exists in that domain and that the domain's authentication type is set to Managed, or gateway pairing will fail[^108]. Assign a single public IP to the FQDN, as multiple IPs per FQDN are not supported[^118]. Install a public certificate whose CN or SAN matches the SBC FQDN, issued by a Certificate Authority in the Microsoft Trusted Root Program with Server Authentication EKU[^107]. Configure TLS 1.2 on CUBE using one of the four supported ECDHE-RSA cipher suites in AES 128 or 256 CBC or GCM mode[^120]. Open firewall ports for SIP/TLS signaling over port 5061 outbound to `sip.pstnhub.microsoft.com`, `sip2.pstnhub.microsoft.com`, and `sip3.pstnhub.microsoft.com` across all Teams IP ranges (52.112.0.0/14 and 52.120.0.0/14) and inbound to the configured CUBE port[^131][^26][^49]. Open media ports towards Microsoft Media Processors[^31].

### Verify
Suggested check: test TLS handshakes to destination port on Direct Routing proxies and verify domain status.

### Rollback
Suggested rollback: delete created firewall rules and revert DNS records.

**Keep carrier trunks on a non-Cisco certified SBC**

### Do
Register the domain portion of the SBC FQDN in the tenant, ensuring it is not `*.onmicrosoft.com`[^111]. Create a user with that domain holding an E3 or E5 licence, and set the domain authentication to Managed[^108]. Install a certificate issued by a Microsoft Trusted Root Program CA with the SBC FQDN in the CN or SAN[^107]. Map a single IP to the SBC FQDN[^118]. Enable TLS 1.2 using supported ECDHE-RSA ciphers[^120]. Allow SIP/TLS traffic outbound on port 5061 to the Microsoft SIP proxy FQDNs across all Microsoft Teams IP ranges[^131][^26][^49].

### Verify
Suggested check: check certificate chain validation on the SBC management interface.

### Rollback
Suggested rollback: disable perimeter firewall rules for Direct Routing signaling.

**Acquire PSTN access from Microsoft Calling Plan**

### Do
Maintain an existing assignment of emergency locations for users in the United States and Canada if a Calling Plan licence is in place before port completion, or assign emergency locations when numbers transfer in[^85].

### Verify
Suggested check: inspect user account usage locations in the admin center.

### Rollback
Suggested rollback: revert tenant domain and usage location settings if required.

**Mix Direct Routing with Calling Plan across populations**

### Do
For Direct Routing populations, complete domain registration, licensed user provisioning, TLS 1.2 ECDHE-RSA configuration, public CA certificate installation, and firewall openings on port 5061 across all Teams IP ranges[^111][^108][^107][^120][^131][^49]. For Calling Plan users, maintain emergency locations and licences before port completion[^85].

### Verify
Suggested check: confirm domain verification and validate network connectivity to Direct Routing signaling endpoints.

### Rollback
Suggested rollback: remove Direct Routing perimeter firewall rules.

## Step 4: Establish PSTN connectivity

**Keep carrier trunks using Cisco CUBE as the SBC**

### Do
Following Microsoft's four-step Direct Routing deployment sequence (connect SBC, enable users, configure routing, translate numbers), pair CUBE to the tenant using PowerShell[^33]:
```powershell
New-CsOnlinePSTNGateway -Fqdn <cube_fqdn> -SipSignalingPort <port> -MaxConcurrentSessions <limit> -Enabled $true
```
[^116]. Keep `SendSIPOptions` enabled (the default) so the gateway remains active in Microsoft monitoring and alerting[^117]. Set the SIP OPTIONS interval per trunk endpoint to the published requirement, which as written sets bounds that read as mutually inconsistent, one transaction every 60 seconds and one every 180 seconds, so confirm the current figure at the source before setting it[^115]. Set `ForwardCallHistory` and `ForwardPai` to `$true` if upstream PBX or carrier services require History-Info, Referred-By, or P-Asserted-Identity headers[^110]. Configure supported codecs (SILK, G.711, G.722, G.729, or AMR-WB in non-bypass) and avoid re-targeting media mid-call, as Teams negotiates the change but will not transmit audio to the new IP[^25][^113].

### Verify
Run `Get-CsOnlinePSTNGateway -Identity <cube_fqdn>` to confirm `Enabled` is `True`, and check CUBE logs to confirm both incoming and outgoing SIP OPTIONS receive 200 OK responses[^122].

### Rollback
Disable outbound traffic by running `Set-CsOnlinePSTNGateway -Identity <cube_fqdn> -Enabled $false`, or remove the gateway entry with `Remove-CsOnlinePSTNGateway`[^116].

**Keep carrier trunks on a non-Cisco certified SBC**

### Do
Execute the Direct Routing deployment flow[^33]. Pair the certified SBC with `New-CsOnlinePSTNGateway` setting `-Fqdn`, `-SipSignalingPort`, `-MaxConcurrentSessions`, and `-Enabled $true`[^116]. Keep `SendSIPOptions` enabled for alerting and monitoring[^117], and set the OPTIONS interval to the published requirement, which as written sets bounds that read as mutually inconsistent, one transaction every 60 seconds and one every 180 seconds, so confirm the current figure at the source first[^115]. Ensure offered codecs match SILK, G.711, G.722, G.729, or non-bypass AMR-WB[^25].

### Verify
Verify that `Get-CsOnlinePSTNGateway` displays `Enabled: True` and that bidirectional 200 OK responses occur for SIP OPTIONS[^122].

### Rollback
Run `Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -Enabled $false` to suspend the gateway[^116].

**Acquire PSTN access from Microsoft Calling Plan**

### Do
Submit a port request, ensuring the billing telephone number matches losing service provider records exactly and verifying that any account freeze has been removed to avoid rejection[^83]. If porting numbers previously registered in Direct Routing, unassign them and release them from tenant inventory using `New-CsOnlineTelephoneNumberReleaseOrder` prior to the port event[^81].

### Verify
Check that the port request transitions to Approved (FOCAccepted) in Order history, and confirm Calling Plan licences and emergency locations are assigned to target users in the US and Canada prior to completion[^85].

### Rollback
Cancel the port request prior to the firm order commitment date[^83].

**Mix Direct Routing with Calling Plan across populations**

### Do
Pair the SBC for Direct Routing populations using `New-CsOnlinePSTNGateway`[^116]. For Calling Plan users, initiate carrier port requests ensuring matching billing telephone numbers and lifting account freezes[^83]. Release any Direct Routing numbers with `New-CsOnlineTelephoneNumberReleaseOrder` before porting them to Calling Plan[^81].

### Verify
Confirm Direct Routing gateway shows `Enabled: True` via `Get-CsOnlinePSTNGateway`[^122], and confirm port orders display Approved (FOCAccepted) status[^85].

### Rollback
Disable the gateway using `Set-CsOnlinePSTNGateway -Enabled $false` and cancel pending port orders[^116][^83].

## Step 5: Configure voice routing policies

**Keep carrier trunks using Cisco CUBE as the SBC**

### Do
Create Direct Routing call routing components: online voice routing policies containing PSTN usages, PSTN usages containing voice routes, and voice routes linking number patterns to online PSTN gateways[^90]. Execute the PowerShell cmdlet sequence: create the usage with `Set-CsOnlinePstnUsage`, define routes with `New-CsOnlineVoiceRoute` (specifying `-NumberPattern`, `-OnlinePstnGatewayList`, `-Priority`, and `-OnlinePstnUsages`), create custom policies with `New-CsOnlineVoiceRoutingPolicy`, and assign them using `Grant-CsOnlineVoiceRoutingPolicy`[^88]. Arrange PSTN usages deliberately, as usages evaluate in sequential order and evaluation stops at the first match[^96]. To configure active/backup CUBE routing, define two separate voice routes with different priorities, because multiple SBCs listed within a single voice route are selected in random order[^94]. Assign routing policies directly to specific users rather than altering the global policy, to prevent Calling Plan users from inadvertently sending calls to CUBE[^91]. Configure a catch-all voice route, as calls made by users lacking a Calling Plan licence will be dropped if no pattern matches[^93].

### Verify
Check policy assignment with `Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy`[^88]. Run the Direct Routing self-diagnostics tool in the Microsoft 365 admin center (not supported in Government, 21Vianet, or Germany clouds)[^95].

### Rollback
Unassign the policy with `Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null` and remove routes with `Remove-CsOnlineVoiceRoute`[^88].

**Keep carrier trunks on a non-Cisco certified SBC**

### Do
Build the routing policy hierarchy using `Set-CsOnlinePstnUsage`, `New-CsOnlineVoiceRoute`, `New-CsOnlineVoiceRoutingPolicy`, and `Grant-CsOnlineVoiceRoutingPolicy`[^90][^88]. Sequence usages deliberately to control route evaluation[^96]. Configure route priorities rather than multi-SBC route lists to establish primary and backup paths[^94]. Avoid modifying the global voice routing policy to prevent tenant-wide inheritance[^91], and define catch-all patterns so unmatched calls are not dropped[^93].

### Verify
Confirm user policy assignment via `Get-CsOnlineUser` and execute the tenant self-diagnostics tool[^88][^95].

### Rollback
Run `Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null` to remove custom routing[^88].

**Acquire PSTN access from Microsoft Calling Plan**

### Do
Do not assign custom online voice routing policies or modify the global policy, ensuring Calling Plan users route through Microsoft PSTN infrastructure without diversion to external trunks[^91]. Assign numbers directly to users and voice application resource accounts[^82].

### Verify
Run `Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy` and confirm the value is empty[^88]. Suggested check: place an outbound call to an external number from a test user client.

### Rollback
If a voice routing policy was assigned in error, clear it with `Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null`[^88].

**Mix Direct Routing with Calling Plan across populations**

### Do
Configure PSTN usages, voice routes, and custom online voice routing policies strictly for the Direct Routing user population[^90][^88]. Leave the global voice routing policy unassigned to prevent Calling Plan users from inheriting trunk routes[^91]. Note that if a user holds both a voice routing policy and a Calling Plan licence, Teams evaluates the voice route policy first and only routes via Calling Plan if no route patterns match[^93].

### Verify
Run `Get-CsOnlineUser` across both populations to confirm Direct Routing users hold the custom policy while Calling Plan users have no assigned policy[^88].

### Rollback
Clear voice routing policies from affected users with `Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null`[^88].

## Step 6: Rebuild dial plan normalization and trunk translation rules

### Do
Order normalization rules top-down with restrictive patterns above permissive patterns, because Teams terminates traversal at the first matching rule[^21]. Manage dial plans using `New-CsTenantDialPlan`, `Set-CsTenantDialPlan`, and `Grant-CsTenantDialPlan`[^19]. To avoid double normalization, Microsoft recommends normalizing numbers to include a plus sign in the dial plan and removing the plus sign using route-based translation rules if an SBC or carrier requires local digit formats[^20]. Create SBC translation rules with `New-CsTeamsTranslationRule` and attach them to the gateway using `InboundTeamsNumberTranslationRules`, `InboundPSTNNumberTranslationRules`, `OutboundTeamsNumberTranslationRules`, or `OutboundPSTNNumberTranslationRules`[^139]. Note that translation rules apply at the SBC level in the order listed[^142]. Apply inbound translation rules where incoming carrier strings diverge from user assigned numbers, because Teams matches inbound calls using Reverse Number Lookup on the received string[^140]. Maintain total translation rules within the 400-rule limit, with maximum pattern lengths under 1024 symbols and translation lengths under 256 symbols[^141]. Verify user usage locations, because when no dial plan rule matches, the Teams service dial plan automatically prepends the country code matching the dialling user's usage location[^22].

### Verify
Test dial plan normalization using PowerShell:
```powershell
Test-CsEffectiveTenantDialPlan -DialedNumber <digits> -Identity <upn>
```
[^19]. Suggested check: examine SBC SIP signalling to verify that outbound Request-URIs reflect the formatting expected by the carrier.

### Rollback
Detach translation rules using `Set-CsOnlinePSTNGateway` with empty rule lists[^139]. Revert user dial plans with `Grant-CsTenantDialPlan -Identity <upn> -PolicyName $null`[^19].

## Step 7: Configure call routing between CUCM and Teams

**Phased coexistence with parallel call routing**

### Do
Configure a SIP trunk on CUCM pointing to CUBE following Cisco's documented task order: build the SIP profile, configure the SIP trunk security profile (setting TLS encryption and digest authentication), and then configure the SIP trunk[^18]. Assign up to 16 destination addresses per CUCM SIP trunk using IPv4, IPv6, FQDNs, or a single DNS SRV record[^16]. Cisco documents CUBE as bridging enterprise and PSTN networks to cloud services including MS Teams Direct Routing, and Cisco's interoperability portal publishes dedicated application notes for Direct Routing with CUCM via CUBE[^10][^5]. For each migrated user, decommission the directory number on CUCM and add a translation pattern that rewrites the internal extension to E.164 and reroutes it with a calling search space towards a route pattern pointing to CUBE[^17][^15]. In Teams, define voice routes directing unmigrated extension ranges to the CUBE gateway[^88]. Note that on transferred or forwarded calls where the ingress SBC is also a valid egress SBC, Direct Routing prioritises that ingress SBC regardless of route priority values[^92].

### Verify
Suggested check: place bidirectional test calls between unmigrated desk phones and migrated clients, test calls between migrated clients and external PSTN numbers, and transfer an inbound call back out to verify ingress SBC handling.

### Rollback
Delete the translation pattern on CUCM and restore the directory number to service[^17].

**Site-by-site flash cutover in scheduled maintenance windows**

### Do
Establish the CUCM-to-CUBE trunk following the profile, security profile, and trunk task order[^18]. Configure site-level route patterns on CUCM pointing to a route list containing the CUBE trunk[^15], keeping them in an isolated partition until cutover. Pre-configure Teams voice routes and gateway translation rules matching site number blocks[^88][^139].

### Verify
Suggested check: execute a pre-cutover rehearsal using a non-production test number routed through the trunk to the cloud and back.

### Rollback
Move site route patterns back to the isolated partition in CUCM and restore local device line assignments[^15].

## Step 8: Configure emergency calling

**Certified Emergency Routing Service provider**

### Do
Configure emergency call routing policies, which Direct Routing requires because emergency call paths depend on client type, country network, and PSTN model[^35]. Enable PIDF-LO on the gateway by setting `Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -PidfloSupported $true` or toggling the setting in Teams admin center so location data is included in outgoing emergency INVITEs[^41]. Contract a certified Direct Routing emergency provider: Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service, or Inteliquent, noting Microsoft may reject support cases involving uncertified providers[^105]. Configure trusted IP addresses and network sites for dynamic emergency enablement and security desk notifications[^36]. Define Location Information Service entries, noting LIS resolves client locations by checking WAP, Ethernet switch and port, Ethernet switch, and subnet in order[^39]. Assign emergency calling policies for security desk alerts, noting a policy assigned to a network site overrides a user policy when the user is located at that site[^42][^44].

### Verify
Allow up to four hours for network settings changes to propagate to clients[^43]. Coordinate a live test call with the ERS provider, noting that the 933 test dial string applies to Calling Plan, Operator Connect, and Teams Phone Mobile, not Direct Routing[^45].

### Rollback
Set `PidfloSupported` to `$false` with `Set-CsOnlinePSTNGateway`[^41]. Suggested rollback: revert emergency routing on the border element to route outbound emergency calls through existing on-premises trunks.

**SBC ELIN application**

### Do
Configure an Emergency Location Identification Number application on the SBC as the documented alternative to an ERS provider[^37]. Set `PidfloSupported` to `$true` on the gateway to pass location attributes to the SBC[^41]. Note that Microsoft's certified SBC table marks Cisco CUBE as 911-service-provider capable but leaves the ELIN-capable column blank[^11]. Configure trusted IP addresses and network sites for dynamic location discovery and security desk notifications[^36]. Populate LIS network identifiers (WAP, switch/port, switch, subnet)[^39], and assign emergency call routing policies[^35].

### Verify
Allow up to four hours for network setting propagation[^43]. Suggested check: place a test emergency call from each designated ELIN zone to confirm the delivered ELIN matches the floor and building with the test operator.

### Rollback
Suggested rollback: reroute emergency patterns on the SBC back to PBX route patterns.

**Microsoft-managed emergency routing**

### Do
Assign validated emergency addresses with geocodes to user phone numbers during assignment[^85][^38]. Configure trusted IP addresses for dynamic emergency calling and network sites for dynamic security desk notification[^36]. Apply emergency calling policies to define emergency dial strings and notification targets, noting site policies override user policies when the user is on site[^42][^44].

### Verify
In the United States and Canada, place a test call to 933 from a client at the site to verify that the automated service echoes the assigned calling line ID and registered address[^45].

### Rollback
Reassign emergency addresses or modify emergency calling policies via the Teams admin center[^42].

## Step 9: Pilot user migration

### Do
Assign the `UpgradeToTeams` instance of `TeamsUpgradePolicy` to pilot users to place them in Teams Only mode, which is required for Direct Routing so inbound calls land in the Teams client[^150]. Direct Routing is not supported in Islands mode[^32]. If pilot users originate from an on-premises Skype for Business deployment, verify that `RegistrarPool` is homed in `infra.lync.com` and clear any existing on-premises `LineUri` with `Set-CsUser -LineUri $null` prior to assigning numbers online[^146]. Assign phone numbers and enable Enterprise Voice using PowerShell:
```powershell
Set-CsPhoneNumberAssignment -Identity <upn> -PhoneNumber <e164_number> -PhoneNumberType DirectRouting
```
[^147]. If using extension-based routing where users share a base number, append `;ext=<extension>` to the number assignment, ensuring inbound SIP INVITEs carry the full number and extension string[^145]. Note that Cloud Voicemail provisioning occurs automatically upon licence and number assignment[^143].

### Verify
Place test inbound and outbound PSTN calls, perform internal calls between pilot users and CUCM extensions, verify Cloud Voicemail deposit and retrieval, and run Direct Routing self-diagnostics in the Microsoft 365 admin center[^95].

### Rollback
Remove the assigned phone number with `Remove-CsPhoneNumberAssignment` and restore the user's prior coexistence mode[^147][^8]. Reactivate the directory number on CUCM[^17].

## Step 10: Provision or migrate endpoint hardware

**Retire Cisco phones for Teams clients and Teams-certified devices**

### Do
Deploy Microsoft Teams desktop and mobile clients, Teams-certified IP phones, or Common Area Phones, all supported by Direct Routing[^28]. Assign Microsoft Teams Shared Device licences to shared phones and Teams Rooms Pro to conference rooms[^52]. Note that Common Area Phones using Direct Routing do not require Calling Plan licences[^28].

### Verify
Suggested check: sign in to each replacement phone or client and verify incoming and outgoing audio.

### Rollback
Suggested rollback: leave existing desk phones plugged into the local switch and active on the PBX.

**Convert eligible phones to MPP firmware for Teams SIP Gateway**

### Do
Verify that phone models appear on the [Teams SIP Gateway](https://warmtransfer.net/knowledge/teams-sip-gateway) compatibility list: 6821, 6841, 6851, 6861, 6871, 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865 and 8832 running multiplatform firmware (minimum 11.1.1MPP, approved 12-0-7MPP)[^127]. Exclude the 8821 and 8831, which Cisco lists as not eligible to migrate to multiplatform firmware[^74]. Confirm that phones run enterprise firmware 14.2.1SR1 or later before initiating conversion[^76].

Reset each phone to factory default settings, which is required prior to onboarding on SIP Gateway[^134]. Enable users with `Set-CsTeamsCallingPolicy -Identity <policy> -AllowSIPDevicesCalling $true`, allowing up to 24 hours for policy propagation[^133]. Ensure users have a PSTN-enabled phone number[^130]. Configure DHCP option 160 with the regional provisioning URL appended with `/$PSN.xml` (for example, `http://noam.ipp.sdg.teams.microsoft.com/$PSN.xml`)[^136]. Allow outbound firewall access over UDP ports 49152 to 53247 and TCP port 5061 towards 52.112.0.0/14 and 52.122.0.0/15, bypassing HTTP proxies and using IPv4[^135]. Cisco ATA 191 Multiplatform Analog Telephone Adapter is verified for interoperability between Direct Routing and analog devices[^1]; WarmTransfer's reading of the sources is that ATA191-MPP and ATA192-MPP support only static location with SIP Gateway[^124]. Note that compatible Cisco MPP phones discover dynamic location via LLDP only[^126], and SIP Gateway registered address fallback is not supported for Direct Routing[^137]. When assigning SIP devices to call queues, note that SIP Gateway does not publish presence, preventing presence-based queue routing[^129].

### Verify
Check that onboarded devices appear in Teams admin center under Teams devices > SIP devices, place a test call, and confirm paired devices remain connected (SIP Gateway automatically offboards paired devices disconnected for 30 days and unpaired devices after 14 days)[^125].

### Rollback
Cisco states that phones running MPP firmware 11.3.3 or later can be converted back to enterprise firmware without requiring a licence[^78]. Re-register the rolled-back phones to CUCM, noting factory resets during onboarding erase previous configurations[^134].

**Keep phones registered to CUCM for non-migrated users**

### Do
In CUCM, translation patterns manipulate dialled digits and reroute calls with the calling search space configured on the pattern[^17], and a route pattern directs a dial string to a gateway or route list[^15]. Maintain existing CUCM emergency route patterns and configurations for these endpoints, as Direct Routing requires specific emergency call routing policies that do not apply to them[^35].

### Verify
Suggested check: verify two-way calling between a desk phone and a migrated client.

### Rollback
Suggested rollback: leave existing desk phones registered to the local call manager.

## Step 11: Recreate hunt groups and voice applications

### Do
Convert CUCM hunt pilots to Microsoft Teams call queues, placing an auto attendant in front of each queue to manage holiday and after-hours schedules, as call queues lack native holiday and business-hour routing[^153]. Create a resource account for each queue and attendant, assign a Microsoft Teams Phone Resource Account licence, and assign the former hunt pilot DID to the resource account[^52][^154]. Note that internal Teams users call the resource account directly while external PSTN callers dial the assigned DID[^154]. Replicate hunt group timeout and busy policies using call queue exception handling to redirect callers to people, voicemail, secondary queues, or auto attendants when queues exceed size or wait limits or have no signed-in agents[^152]. Note that Microsoft Media Processors are always inserted in the media path for auto attendants and call queues[^65].

### Verify
Suggested check: place external and internal test calls to each resource account DID, testing business-hours, after-hours, timeout redirects, and overflow thresholds.

### Rollback
Unassign the DID from the resource account and repoint incoming carrier routes to the CUCM hunt pilot[^154].

## Step 12: Configure branch survivability

**No branch survivability appliance**

### Do
Document WAN outage risks per branch location, noting that Direct Routing media routes through Microsoft Media Processors across the WAN by default unless media bypass is active[^31].

### Verify
Suggested check: confirm documented risk sign-off and mobile calling procedures for branch sites.

### Rollback
Suggested rollback: retain existing branch WAN configuration.

**Deploy Survivable Branch Appliances**

### Do
Obtain the Survivable Branch Appliance package from your SBC vendor, as Microsoft provides the SBA as distributable code embedded in vendor firmware or hosted on a separate VM[^100]. Enable media bypass on the SBC gateway using `Set-CsOnlinePSTNGateway -Identity <sbc_fqdn> -MediaBypass $true`, which keeps media local between the client and SBC[^58][^64][^104]. Open firewall ports 3443, 4444, and 8443 from SBA to Teams clients, port 5061 between SBA and SBC, UDP port 123 for NTP, and port 443 outbound to Microsoft 365, ensuring TLS 1.2 is enabled on the SBA OS[^104]. Configure SBA policies using Teams PowerShell cmdlets (`New-CsTeamsSurvivableBranchAppliance`, `New-CsTeamsSurvivableBranchAppliancePolicy`, and `Grant-CsTeamsSurvivableBranchAppliancePolicy`), as the Teams admin center does not support SBA configuration[^99]. Note SBA operating limits: SBA supports physical Windows desktop, macOS desktop, and Teams phone clients (excluding VMs and web clients)[^98]; during outages, clients can place/receive PSTN calls, hold, resume, blind transfer, and forward, but emergency location information is not shared during emergency calls[^103][^101]. Ensure regular voice routes contain patterns matching raw emergency dial strings without a leading plus, as SBA bypasses normalization and does not support emergency call routing policies[^102]. If Continuous Access Evaluation is enabled in the tenant, note that SBA remains operational for approximately 30 minutes during an outage unless CAE is disabled[^97].

### Verify
Validate media bypass prior to branch deployment by setting up a secondary trunk with a separate FQDN and ports for staged testing[^63]. Suggested check: simulate a WAN failure at a branch and confirm physical desktop clients transition to SBA mode and place PSTN calls.

### Rollback
Unassign SBA policies from branch users with `Grant-CsTeamsSurvivableBranchAppliancePolicy -PolicyName $null` and disable media bypass on the gateway with `Set-CsOnlinePSTNGateway -MediaBypass $false`[^99][^64].

**Retain CUCM or SRST locally for registered devices**

### Do
Retain local call control for locally registered IP phones during WAN disruptions, routing calls to gateways and trunks using CUCM route patterns[^15]. 

### Verify
Suggested check: isolate branch WAN connectivity and verify that local desk phones fall back to survivable gateways and place PSTN calls.

### Rollback
Suggested rollback: retain local call routing configurations on branch gateways.

## Step 13: Execute migration cutover

**Phased coexistence with parallel call routing**

### Do
Migrate user batches iteratively by assigning Teams Only mode, allocating phone numbers, and applying voice routing policies[^150][^147][^88]. Monitor Direct Routing SBC availability: Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last 3 regular one-minute intervals, demoting unresponsive SBCs from active routing[^70]. When `MaxConcurrentSessions` is set, alerting notifies the administrator at 90 percent or more of that value, and when it is not set no alerts are generated[^106]. Check SBC logs directly for pairing failures or rejected INVITEs (such as invalid FQDNs), because Call Analytics captures only failures that reach internal Teams components[^68].

### Verify
Suggested check: confirm in Call Quality Dashboard and SBC logs that inbound and outbound calls complete without gateway demotion or SIP errors.

### Rollback
Per user, clear the Teams number assignment and restore the directory number and line appearance on CUCM[^147][^17].

**Site-by-site flash cutover in scheduled maintenance windows**

### Do
During the scheduled cutover window, switch CUCM site route patterns to route all site number blocks across the SIP trunk to CUBE[^15]. Grant the online voice routing policy to all site users and assign their phone numbers[^88][^147]. Monitor SBC logs and concurrent call capacity in real time during the cutover[^106][^68].

### Verify
Suggested check: test the main site pilot number, selected individual DIDs, hunt group numbers, and an emergency call within the maintenance window.

### Rollback
Revert CUCM route patterns to their original pre-cut partitions to return call routing to local CUCM lines[^15].

## Step 14: Decommission migrated CUCM resources

### Do
Following post-cutover stabilization, delete migrated directory numbers, translation patterns, and device associations from CUCM[^17]. Maintain the CUCM-to-CUBE coexistence trunk until all tenant populations have cut over[^15]. If the organisation operated an integrated Skype for Business Server environment, assign TeamsOnly mode tenant-wide only after all on-premises users are migrated with `Move-CsUser` and Skype for Business DNS records are repointed to Microsoft 365[^9]. If numbers are being transitioned from Direct Routing to Microsoft Calling Plan, release them from tenant inventory using `New-CsOnlineTelephoneNumberReleaseOrder`[^81].

### Verify
Suggested check: confirm no active registrations or call traffic remain on decommissioned nodes.

### Rollback
Suggested rollback: restore deleted configurations from the pre-maintenance cluster backup.

## Applicability

Applies to: Microsoft certified SBC list, Microsoft Teams Phone, Cisco Unified Border Element, Microsoft Teams, Cisco Unified Communications Manager, Microsoft Teams Phone Direct Routing, Microsoft Teams emergency calling, Cisco IP Phone 8800 Series, Cisco collaboration devices, Microsoft Teams Phone Calling Plan, Microsoft Teams SIP Gateway, Microsoft Teams Phone voice applications, Microsoft Teams Phone Calling Plans, Cisco Unified Border Element (CUBE), ISI Telemanagement Solutions migration analytics, Cisco Unified Communications Manager, Cisco Webex Calling, and Cisco. Deployments: on-premises, hybrid, multi-tenant, and on-premises-unified-cm. Sources checked 2026-09-21. The end of software maintenance releases for Version 14 perpetual on-premises calling applications was 7 April 2026[^155], and the last date of support is 30 April 2027[^156]. Cisco CUBE is certified at IOS XE Amsterdam 17.2.1r (recommended 17.6.1a; 17.3.3 for CSR 1000V; Catalyst 8000 Edge supported from 17.3.2)[^13]. Microsoft Direct Routing self-diagnostics are unavailable in Microsoft 365 Government, 21Vianet, or Germany clouds[^95], and SIP Gateway is unavailable in DoD environments[^130].

## What remains uncertain

The specific Cisco IOS XE dial-peer, SIP profile, and trustpoint CLI syntax required on CUBE for Teams Direct Routing is not covered by the sources below. Migration mechanisms for Cisco Unity Connection voicemail greetings and stored messages are not covered by the sources below. Cisco Unified Contact Center Express or Enterprise migration paths are not covered by the sources below. Microsoft's certified SBC table marks Cisco CUBE as certified for non-media bypass and media bypass and marks the 911 service provider capable column as satisfied, but leaves the ELIN capable column blank[^11]. SIP OPTIONS pings must not exceed a frequency of one transaction every 60 seconds and must not be more or less frequent than one transaction every 180 seconds for each configured trunk for each endpoint[^115].

## Sources

[^1]: Cisco ATA 191 Multiplatform Analog Telephone Adapter is verified for interoperability between Direct Routing and analog devices, alongside AudioCodes, Oracle and Ribbon adapters and gateways. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Session Border Controllers certified for Direct Routing > Direct Routing and analog devices interoperability. Checked 2026-09-16.
[^2]: The number of user (subscriber) numbers obtainable from Microsoft equals the total number of Domestic and/or International Calling Plan licences multiplied by 1.1 plus 10 extra numbers, pay-as-you-go licences allow only 1 number each, and these limits exclude numbers that are ported or porting to Microsoft. Source: [Get Microsoft Calling Plan telephone numbers for your organization](https://learn.microsoft.com/en-us/microsoftteams/manage-phone-numbers), Get Microsoft Calling Plan telephone numbers for your organization > How many telephone numbers can you get?. Checked 2026-09-16.
[^3]: New numbers are acquired through the Teams admin center Add phone numbers wizard under Voice > Phone numbers > Add > From Operator, and the Voice option only appears once at least one Enterprise E5 or E3 licence, one Phone System add-on licence, or one Audio Conferencing add-on licence is owned. Source: [Get Microsoft Calling Plan telephone numbers for your organization](https://learn.microsoft.com/en-us/microsoftteams/manage-phone-numbers), Get Microsoft Calling Plan telephone numbers for your organization > Get new phone numbers, steps 1-4. Checked 2026-09-16.
[^4]: With Microsoft Teams Calling Plan, PSTN access, phone numbers, emergency screening service in the U.S. and support come from Microsoft with a 99.999% reliability Service Level Agreement. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options > Microsoft Teams Calling Plan bullet. Checked 2026-09-16.
[^5]: Cisco's Unified Border Element interoperability portal publishes three Microsoft Direct Routing documents: Direct Routing for Microsoft Phone System with CUBE and Direct Routing for Microsoft Phone System with Cisco UCM via CUBE, both labelled CUBE Release 14.4, and a multi-tenant Direct Routing with CUBE-HA guide labelled IOS-XE 17.9.1a. Source: [Cisco Unified Border Element (CUBE) / SIP Trunking Solutions](https://www.cisco.com/c/en/us/solutions/enterprise/interoperability-portal/networking_solutions_products_genericcontent0900aecd805bd13d.html), Interoperability portal document list, Microsoft Phone System entries. Checked 2026-09-21.
[^6]: Cisco files the CUCM-via-CUBE Direct Routing note under the 'Cisco Unified Border Element to Third-Party IP PBX' grouping, described as notes on connecting CUBE to various non-Cisco devices using SIP or H.323, and the portal page states no certification status for these Direct Routing documents. Source: [Cisco Unified Border Element (CUBE) / SIP Trunking Solutions](https://www.cisco.com/c/en/us/solutions/enterprise/interoperability-portal/networking_solutions_products_genericcontent0900aecd805bd13d.html), Cisco Unified Border Element (CUBE) / SIP Trunking Solutions > Cisco Unified Border Element to Third-Party IP PBX (section intro) and the Direct Routing entries. Checked 2026-09-16.
[^7]: Cisco's CUBE interoperability portal lists 'Direct Routing for Microsoft Phone System with Cisco Unified Communications Manager (UCM) via CUBE' and 'Direct Routing for Microsoft Phone System with Cisco Unified Border Element (CUBE)' under CUBE Release 14.4, and 'Deploying a Multi-tenant Direct Routing for Microsoft Phone System with CUBE-HA' at IOS-XE 17.9.1a under CUBE Release 14.6. Source: [Cisco Unified Border Element (CUBE) / SIP Trunking Solutions](https://www.cisco.com/c/en/us/solutions/enterprise/interoperability-portal/networking_solutions_products_genericcontent0900aecd805bd13d.html), Cisco Unified Border Element (CUBE) / SIP Trunking Solutions > Cisco Unified Border Element to Third-Party IP PBX > CUBE Release 14.6 and CUBE Release 14.4 groupings. Checked 2026-09-16.
[^8]: The coexistence modes an administrator can set are Islands, Skype for Business only, Skype for Business with Teams collaboration, Skype for Business with Teams collaboration and meetings, and Teams only, and only users homed in the cloud can be given TeamsOnly mode while the other modes apply only to users homed in Skype for Business Server on-premises. Source: [Set your coexistence and upgrade settings](https://learn.microsoft.com/en-us/microsoftteams/setting-your-coexistence-and-upgrade-settings), Set upgrade options for a single user in your organization, step 3. Checked 2026-09-21.
[^9]: TeamsOnly mode can be assigned to an entire tenant only after all on-premises users have been moved to Teams Only with Move-CsUser in the Skype for Business Server toolset and any Skype for Business DNS records have been repointed to Microsoft 365. Source: [Set your coexistence and upgrade settings](https://learn.microsoft.com/en-us/microsoftteams/setting-your-coexistence-and-upgrade-settings), Set upgrade options for all users in your organization, Important callout under 'Teams only'. Checked 2026-09-21.
[^10]: Cisco documents Cisco Unified Border Element as able to bridge enterprise and PSTN with cloud calling services such as Webex Calling and MS Teams Direct Routing, and describes CUBE as a network-to-network demarcation interface for signalling and media interworking, address and port translation, billing, security, quality of service, call admission control and bandwidth management. Source: [Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - Overview of Cisco Unified Border Element](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/voice/cube/ios-xe/config/ios-xe-book/voi-cube-overview.html), Overview of Cisco Unified Border Element, capability list. Checked 2026-09-21.
[^11]: Microsoft's table marks Cisco CUBE as certified for both non-media bypass and media bypass, and leaves the 'ELIN capable' column blank for Cisco CUBE while marking the 911 service provider capable column as satisfied. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table > Cisco rows, Media bypass and ELIN capable columns. Checked 2026-09-16.
[^12]: Cisco Unified Border Element (CUBE) is certified for Direct Routing on ISR 1000 Series, ISR 4000 Series, CSR 1000V, ASR 1000 Series and Catalyst 8000 Edge Platforms. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Session Border Controllers certified for Direct Routing > Certified SBC vendors > Cisco rows. Checked 2026-09-16.
[^13]: The Cisco CUBE rows are certified at IOS XE Amsterdam 17.2.1r (recommended 17.6.1a; 17.3.3 for CSR 1000V; Catalyst 8000 Edge supported from 17.3.2), and the table notes that firmware higher than documented is supported as long as the major.minor version is unchanged. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors > Cisco rows, Software version column; and the firmware-version note above the table. Checked 2026-09-16.
[^14]: Cisco does not appear in the Microsoft page's 'Support for Local Media Optimization' vendor table, which lists AudioCodes, Ribbon, TE-SYSTEMS, Oracle, Avaya, Italtel and Enghouse Networks (inferred). Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Session Border Controllers certified for Direct Routing > Support for Local Media Optimization. Checked 2026-09-16.
[^15]: In Cisco Unified Communications Manager a route pattern directs a matching dial string to a gateway or to a route list, a route list is a prioritised list of the available paths for the call, and a route group distributes the call to gateways and trunks. Source: [System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010010.html), Configure Call Routing > route pattern, route list and route group definitions. Checked 2026-09-21.
[^16]: A Cisco Unified Communications Manager SIP trunk can be assigned up to 16 different destination addresses using IPv4 or IPv6 addressing, fully qualified domain names, or a single DNS SRV record. Source: [System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_01000.html), Configure Trunks > SIP Trunk Overview. Checked 2026-09-21.
[^17]: A Cisco Unified Communications Manager translation pattern manipulates the dialled digits first and then reroutes the call using the calling search space configured within that pattern. Source: [System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Call Routing](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_010010.html), Configure Call Routing > translation pattern description. Checked 2026-09-21.
[^18]: The Cisco Unified Communications Manager trunk configuration task flow is to configure a SIP profile, then a SIP trunk security profile carrying settings such as TLS signalling encryption and digest authentication, then the SIP trunk that applies both profiles. Source: [System Configuration Guide for Cisco Unified Communications Manager Release 15 and SUs - Configure Trunks](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/systemConfig/cucm_b_system-configuration-guide-15/cucm_b_system-configuration-guide-14_chapter_01000.html), Configure Trunks > Trunk Configuration Task Flow. Checked 2026-09-21.
[^19]: Tenant dial plans are managed with New-CsTenantDialPlan, Set-CsTenantDialPlan and Grant-CsTenantDialPlan, and the result for a given user and dialled number is checked with Get-CsEffectiveTenantDialPlan and Test-CsEffectiveTenantDialPlan. Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Using PowerShell > Using single cmdlets. Checked 2026-09-21.
[^20]: Microsoft recommends that Direct Routing customers use dial plans that normalise numbers to include a plus and then remove the plus with a route-based translation rule, to avoid double normalisation. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Route-based number translations - for outbound calls, Note. Checked 2026-09-21.
[^21]: Teams traverses a dial plan's normalization rules from the top down and uses the first rule that matches the dialled number, so more restrictive rules must be sorted above less restrictive ones. Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Using the Microsoft Teams admin center > Create a dial plan, Note at step 4. Checked 2026-09-21.
[^22]: Where the user's effective dial plan applies no normalisation rule to the dialled number, the Teams service dial plan prepends +CC using the country or region code of the dialling user's usage location, for Calling Plans, Direct Routing and PSTN conference dial-out. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Route-based number translations - for outbound calls, Note. Checked 2026-09-21.
[^23]: Under Direct Routing the organisation can use any PSTN operator, with the integration achieved through a certified SBC procured, installed and managed by the customer, its integrator, or a Direct-Routing-as-a-Service provider. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options > Direct Routing bullet and its sub-bullet. Checked 2026-09-16.
[^24]: Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used, and Microsoft reserves the right to decline support cases where a non-certified device is connected. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Support boundaries. Checked 2026-09-16.
[^25]: Direct Routing supports SILK, G.711, G.722, G.729, and AMR-WB (non-bypass only) between Microsoft Teams and the SBC, and Microsoft does not support media re-targeting during an active Direct Routing call. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Supported codecs (including the note following the list). Checked 2026-09-16.
[^26]: Direct Routing SIP signalling targets three FQDNs in priority order - sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com - resolving into 52.112.0.0/14 and 52.120.0.0/14, over SIP/TLS to destination port 5061. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > SIP signalling: FQDNs and SIP signalling ports. Checked 2026-09-16.
[^27]: Direct Routing connects an organisation's own telephony infrastructure to Microsoft Teams Phone by using a supported, customer-provided Session Border Controller (SBC), which is the mechanism a CUCM estate would use to keep its own PSTN carrier. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > opening paragraph. Checked 2026-09-16.
[^28]: Direct Routing supports Microsoft Teams desktop and mobile clients, Teams-certified phones and Common Area Phones, and a Calling Plan licence isn't required for Common Area Phones when Direct Routing is used. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Supported endpoints. Checked 2026-09-16.
[^29]: Direct Routing can be deployed alongside Microsoft Calling Plan, Operator Connect and Teams Phone Mobile in the same tenant, with a common pattern being Calling Plan or Operator Connect for PSTN calling and Direct Routing for third-party PBXs, analog devices and specialised routing. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Direct Routing with Calling Plan and Operator Connect. Checked 2026-09-16.
[^30]: A Direct Routing deployment requires a Microsoft-certified SBC, one or more PSTN trunks connected to the SBC, a Microsoft 365 tenant hosting Teams users homed online, one or more verified domains (not *.onmicrosoft.com), a public IP reachable by Teams, an SBC FQDN registered in the tenant, a public DNS entry for that FQDN, and a trusted public certificate. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Infrastructure requirements. Checked 2026-09-16.
[^31]: Media traffic on Direct Routing uses Microsoft Media Processors unless Media Bypass is enabled. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Media traffic. Checked 2026-09-16.
[^32]: Direct Routing isn't supported in Islands mode. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Licensing requirements > Note. Checked 2026-09-16.
[^33]: Microsoft's four Direct Routing configuration steps are: connect the SBC with Teams Phone and validate the connection; enable users for Direct Routing, voice and voicemail; configure call routing; and translate numbers to an alternate format. Source: [Configure Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-configure), Configure Direct Routing > numbered step list. Checked 2026-09-16.
[^34]: Teams distinguishes an emergency address (a civic street address), a place (typically a floor, building, wing or office number associated with that address), an emergency location (a civic address with an optional place, carrying a unique location ID), and a registered address (the address assigned to a user, also called the static emergency address or address of record). Source: [Plan and manage emergency calling](https://learn.microsoft.com/en-us/microsoftteams/what-are-emergency-locations-addresses-and-call-routing), Plan and manage emergency calling > Emergency address (definitions table). Checked 2026-09-16.
[^35]: Emergency call routing determines how an emergency call reaches the PSAP and depends on the country's emergency calling network, the client type and the PSTN connectivity option; Direct Routing requires configuring specific emergency call routing policies, whereas with other connectivity options the carrier handles much of the routing configuration. Source: [Plan and manage emergency calling](https://learn.microsoft.com/en-us/microsoftteams/what-are-emergency-locations-addresses-and-call-routing), Plan and manage emergency calling > Emergency call routing. Checked 2026-09-16.
[^36]: For Direct Routing users, dynamic enablement of emergency calling or dynamic configuration of security desk notification requires both trusted IP addresses and network sites to be configured; if only dynamic locations are required, trusted IP addresses alone are enough. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Configure network settings, 'For Direct Routing users' list. Checked 2026-09-21.
[^37]: For Direct Routing the organisation must either configure a connection to an Emergency Routing Service provider in the United States and Canada or configure the SBC for an Emergency Location Identification Number application. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Emergency calling prerequisites for Direct Routing > Set up an Emergency Routing Service provider. Checked 2026-09-21.
[^38]: To assign an emergency location to a network identifier for dynamic emergency calling, the emergency address must contain an appropriate geo code, and Microsoft recommends creating addresses with the Teams admin center map search so they are formatted, validated and geo-coded automatically. Source: [Plan and manage emergency calling](https://learn.microsoft.com/en-us/microsoftteams/what-are-emergency-locations-addresses-and-call-routing), Plan and manage emergency calling > Emergency address > Emergency address geo codes (including the Important note). Checked 2026-09-16.
[^39]: The Location Information Service returns a location by matching the client's network connectivity in the order WAP, Ethernet switch and port, Ethernet switch, then subnet, and the first match is used. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Plan for emergency calling, step 2 LIS match list. Checked 2026-09-21.
[^40]: Dynamic emergency calling including security desk notification is not supported on the Teams web client, and Microsoft's remedy is to turn off the Web PSTN calling setting in a Teams calling policy assigned to web client users. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Supported clients, Note after the client list. Checked 2026-09-21.
[^41]: For Direct Routing the peer PSTN gateway must be told to add location information to the outgoing emergency INVITE by setting PidfloSupported to true, either with Set-CsOnlinePSTNGateway -PidfloSupported $true or the 'SBC supports PIDF/LO for emergency calls' toggle in Teams admin center. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Emergency calling prerequisites for Direct Routing > Change PIDF/LO in Teams admin center and in PowerShell. Checked 2026-09-21.
[^42]: Emergency calling policies in Teams apply when Calling Plans, Operator Connect, Teams Phone Mobile or Direct Routing is the PSTN connectivity option, and let an administrator allow end users to configure their emergency address at remote locations, configure emergency numbers, and configure who is notified when a user calls emergency services. Source: [Manage emergency calling policies in Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/manage-emergency-calling-policies), Manage emergency calling policies in Microsoft Teams > intro and 'The emergency calling policy enables you to' list. Checked 2026-09-16.
[^43]: Some changes to network settings such as a new address or network identifier can take up to four hours to propagate and become available to Teams clients. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Configure network settings, paragraph after the trusted IP note. Checked 2026-09-21.
[^44]: If an emergency calling policy is assigned to a network site and to a user, and the user is at that network site, the policy assigned to the network site overrides the policy assigned to the user. Source: [Manage emergency calling policies in Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/manage-emergency-calling-policies), Manage emergency calling policies in Microsoft Teams > second paragraph. Checked 2026-09-16.
[^45]: The 933 test number validates emergency configuration for Calling Plan, Operator Connect and Teams Phone Mobile users in the United States and Canada, while Direct Routing customers in the United States should coordinate with their Emergency Routing Service provider for a test service. Source: [Configure dynamic emergency calling](https://learn.microsoft.com/en-us/microsoftteams/configure-dynamic-emergency-calling), Test emergency calling. Checked 2026-09-21.
[^46]: A vendor page states that Cisco has announced end of life for CUCM v12.5 and v14, without giving any end-of-sale or end-of-support dates (field report). Source: [Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide](https://isianalytics.com/migrating-from-cucm-to-teams-phone/), Migrating from CUCM to Microsoft Teams? > migration drivers / lifecycle section. Checked 2026-09-16.
[^47]: A vendor of migration analytics markets simultaneous CUCM and Teams reporting as necessary during phased migrations, which is evidence that phased coexistence between CUCM and Teams Phone is the common field pattern rather than a single cutover (field report). Source: [Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide](https://isianalytics.com/migrating-from-cucm-to-teams-phone/), Migrating from CUCM to Microsoft Teams? > phased migration / reporting sections. Checked 2026-09-16.
[^48]: A migration-analytics vendor states that native Microsoft Teams reporting retains call history for 27 days, with a 28-day EUII policy in Call Quality Dashboard (field report). Source: [Migrating from Cisco UCM to Microsoft Teams Phone | 2026 Guide](https://isianalytics.com/migrating-from-cucm-to-teams-phone/), Migrating from CUCM to Microsoft Teams? > reporting limitations section. Checked 2026-09-16.
[^49]: Firewalls must allow Direct Routing signalling traffic to and from all Microsoft Teams IP ranges, not only the addresses returned by a DNS query for the SIP proxy FQDNs. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling: FQDNs, Important callout after the IP range list. Checked 2026-09-21.
[^50]: All users who need their own telephone number must be licensed for the Microsoft Teams and Microsoft 365 Phone System applications; where any Microsoft 365 E5 licence is used it is not necessary to also assign the standalone Microsoft Teams Phone Standard licence. Source: [Teams Phone licensing](https://learn.microsoft.com/en-us/microsoftteams/teams-phone-licensing), Licensing Teams Phone - for end users. Checked 2026-09-16.
[^51]: If Microsoft provides the PSTN access and phone numbers, the user additionally requires a Microsoft Calling Plan licence; if a non-Microsoft PSTN operator is used, Microsoft requires no other licensing because the PSTN costs are incurred from that operator. Source: [Teams Phone licensing](https://learn.microsoft.com/en-us/microsoftteams/teams-phone-licensing), Licensing Teams Phone - adding PSTN. Checked 2026-09-16.
[^52]: Common area telephones use the Microsoft Teams Shared Device licence, Teams Rooms use Teams Room Pro, and voice applications such as auto attendants and call queues use the Microsoft Teams Phone Resource Account licence; the Phone System application is included in the shared device licences. Source: [Teams Phone licensing](https://learn.microsoft.com/en-us/microsoftteams/teams-phone-licensing), Licensing Teams Phone - for shared devices and Licensing Teams Phone - for voice applications. Checked 2026-09-16.
[^53]: Because a user can have multiple endpoints, support of SIP 183 is not possible on inbound bypassed calls and Direct Routing always uses 180 Ringing in that case. Source: [Configure Local Media Optimization for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization-configure), Call flows > Always Bypass mode > Inbound calls and the user is in the same location as the SBC with Always Bypass. Checked 2026-09-16.
[^54]: Local Media Optimization is configured from the same network settings used by Location-Based Routing and dynamic emergency calling: trusted IP addresses, network regions, network sites and network subnets, plus a virtual topology that assigns SBCs to sites with a mode and a proxy SBC. Source: [Configure Local Media Optimization for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization-configure), Configure Local Media Optimization for Direct Routing > intro and Configure the user and the SBC sites. Checked 2026-09-16.
[^55]: For Local Media Optimization the -MediaBypass parameter must be set to $true, and if the SBC does not have the -BypassMode parameter set then X-MS headers will not be sent. Source: [Configure Local Media Optimization for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization-configure), Define the virtual network topology > notes on the Set-CsOnlinePSTNGateway parameters. Checked 2026-09-16.
[^56]: In split-tunnel VPN scenarios where the Teams client is detected as external but can still reach the internal interface of the Direct Routing SBC, Microsoft signals the external location to the SBC, which can cause prolonged call setup and in some cases no audio on inbound PSTN calls; the page says VPN administrators must block access between remote VPN users and the SBC internal interface. Source: [Configure Local Media Optimization for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization-configure), Configure the user and the SBC sites > Note on split-tunnel VPN. Checked 2026-09-16.
[^57]: When BypassMode is defined, Direct Routing adds X-MS-UserLocation (internal or external), X-MS-MediaPath (the ordered SBC list for the media path, with the final SBC always last) and X-MS-UserSite (the tenant administrator's site string) to SIP INVITEs and re-INVITEs, and the Request-URI targets the SBC FQDN. Source: [Configure Local Media Optimization for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-media-optimization-configure), X-MS Headers introduced in Direct Routing on Invites and Re-Invites if BypassMode is defined (table). Checked 2026-09-16.
[^58]: Media bypass keeps media between the SBC and the client instead of sending it via Microsoft Teams Phone, and to configure it the SBC and the client must be in the same location or network. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), About media bypass with Direct Routing. Checked 2026-09-16.
[^59]: For direct media between a Teams client and the SBC, UDP/SRTP is required on destination ports 50000-50019 at the SBC, whereas media to and from Microsoft Media Processors uses 3478-3481 and 49152-53247. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Media traffic: IP and Port ranges > Requirements for direct media traffic and Requirements for using media processors. Checked 2026-09-16.
[^60]: Media bypass is supported with standalone Teams desktop clients, Android and iOS clients and Teams Phone devices; for other endpoints that don't support media bypass, including Skype for Business 3PIP phones and WebRTC-based web clients, the call is converted to non-bypass automatically. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Client endpoints supported with media bypass. Checked 2026-09-16.
[^61]: Media bypass uses ICE on the Teams client and ICE Lite on the SBC, and Microsoft points readers to RFC 5245 for those protocols. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), About media bypass with Direct Routing, final paragraph. Checked 2026-09-16.
[^62]: Teams Transport Relays have two versions - v4 requiring port range 50000 to 59999 and v6 working with 3478 to 3481 - and Microsoft recommends at least two ports per concurrent call on the SBC. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Requirements for using Transport Relays. Checked 2026-09-16.
[^63]: To move from non-media bypass to media bypass while confirming functionality first, Microsoft documents creating a second trunk with a different FQDN pointing at the same SBC, with different TLS SIP signalling ports, a separate Online Voice Routing policy, and that policy assigned only to identified pilot users. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Configure separate trunks for media bypass and non-media bypass. Checked 2026-09-16.
[^64]: Media bypass is controlled per SBC with the Set-CSOnlinePSTNGateway command and the -MediaBypass parameter set to true or false, and enabling it does not mean all media traffic stays within the corporate network. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), About media bypass with Direct Routing, second paragraph. Checked 2026-09-16.
[^65]: Media Processors are always in the media path for non-bypassed end-user calls and always in the media path for voice applications such as Call Park, Organizational Auto Attendant and Call Queues, and never in the path for bypassed end-user calls. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Use of Media Processors and Transport Relays. Checked 2026-09-16.
[^66]: Media Processors are a B2BUA and can transcode (for example SILK from the Teams client to G.711 toward the SBC), while Transport Relays are not a B2BUA and never change the codec between the client and the SBC even when traffic flows via relays. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Use of Media Processors and Transport Relays > comparison table and transcoding explanation. Checked 2026-09-16.
[^67]: Microsoft's Direct Routing documentation set defines no import path for an existing PBX dial plan and instead has the administrator rebuild routing as tenant dial plans, PSTN usages, voice routes and trunk translation rules; the only documented import is a Skype for Business Server dial plan exported to XML and recreated with New-CsTenantDialPlan (inferred). Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Using PowerShell > Using a PowerShell script, final script importing OPDP1. Checked 2026-09-21.
[^68]: Call Analytics only helps when calls reach the internal Direct Routing components and fail; for SBC pairing problems or rejected INVITEs such as a misconfigured trunk FQDN the administrator must read the SBC logs, to which Direct Routing sends a detailed description of the issue. Source: [Monitor Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-monitor-and-troubleshoot), Monitor Call Quality Analytics dashboard and SBC logs, final paragraph. Checked 2026-09-21.
[^69]: When two or more SBCs in one route are considered healthy and equal, Direct Routing applies a Fisher-Yates shuffle to distribute the calls between them. Source: [Monitor Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-monitor-and-troubleshoot), Monitoring availability of Session Border Controllers ..., final paragraph. Checked 2026-09-21.
[^70]: Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last three regular one-minute intervals, and an SBC that has not is demoted so that it is not tried first, though a demoted SBC is retried before the call fails. Source: [Monitor Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-monitor-and-troubleshoot), Monitoring availability of Session Border Controllers using Session Initiation Protocol (SIP) options messages. Checked 2026-09-21.
[^71]: For non-Webex Calling migrations a per-device licence is required and is node-locked to the phone MAC address, with SKUs L-CP-E2M-88XX-CNV=, L-CP-E2M-78XX-CNV=, L-CP-M2E-88XX-CNV= and L-CP-M2E-78XX-CNV= each paired with a technical-support SKU, while Webex Calling migrations through the Control Hub assistant need no ordered licence. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > licence section and Appendix B (license generation). Checked 2026-09-16.
[^72]: Cisco MPP firmware runs on the 6800, 7800 and 8800 Series, but only the 7800 and 8800 series have the capability to run either MPP firmware or Enterprise firmware. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > firmware migration overview / FAQ. Checked 2026-09-16.
[^73]: Cisco's Enterprise-to-MPP conversion document describes the phones as working with approved third-party call control systems as well as Cisco Webex Calling and cites BroadWorks, BroadCloud and BroadSoft in its FAQ, and does not mention Microsoft Teams anywhere in the content read. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > body and FAQ. Checked 2026-09-16.
[^74]: Cisco lists the 8821 and 8831 as not eligible to migrate to multiplatform firmware. Source: [Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform)](https://www.cisco.com/c/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/guide-c07-742786.html), Eligible 8800 models section, ineligibility sentence. Checked 2026-09-21.
[^75]: The supported conversion routes are the Cloud Upgrader at upgrade.cisco.com, the Webex Control Hub migration assistant (Webex Calling only, licences automated, phones authorised for Webex Calling only), a UCM/CUCM-based manual method that uploads transition firmware and the licence via TFTP File Management, sets the Phone Load, and applies a Transition Authorization Rule, and self-hosted web or TFTP servers. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > table of contents and migration methods sections. Checked 2026-09-16.
[^76]: Cisco's firmware conversion guide states that a phone must run enterprise firmware 14.2.1SR1 or later before conversion to multiplatform firmware, otherwise the documented procedures may not work. Source: [Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform)](https://www.cisco.com/c/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/guide-c07-742786.html), Conversion prerequisites, minimum firmware statement. Checked 2026-09-21.
[^77]: Cisco states that MPP phone firmware does not work and is not supported on Cisco Unified Communications Manager. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > FAQ. Checked 2026-09-16.
[^78]: Cisco states that phones converted to multiplatform firmware 11.3.3 or later can be migrated back to enterprise firmware without needing a licence. Source: [Cisco IP Phone 7800 and 8800 Series firmware conversion guide (Enterprise to Multiplatform)](https://www.cisco.com/c/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/guide-c07-742786.html), Migration back to Enterprise firmware section. Checked 2026-09-21.
[^79]: Phones converted from Enterprise to MPP firmware can be migrated back to Enterprise firmware without needing a licence. Source: [Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware](https://www.cisco.com/c/dam/en/us/products/collateral/collaboration-endpoints/unified-ip-phone-7800-series/firmware-migration-master-guide.pdf), Convert Cisco 7800 and 8800 series IP phones between Enterprise and MPP Firmware > licence section. Checked 2026-09-16.
[^80]: No Microsoft Learn document specific to migrating from Cisco Unified Communications Manager to Teams Phone was located in this run; Microsoft's migration and voice planning content is expressed in terms of PSTN connectivity models, Direct Routing components and device compatibility rather than in terms of replacing a named competitor PBX (inferred). Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing > Why choose Direct Routing? (the page's stated fits, none of which name a vendor PBX). Checked 2026-09-16.
[^81]: When Direct Routing numbers are later ported to another PSTN connectivity option they must first be unassigned and then released from Microsoft's inventory with New-CsOnlineTelephoneNumberReleaseOrder before the port event. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Upload Direct Routing numbers to your tenant > Order history, closing Note. Checked 2026-09-21.
[^82]: Microsoft Calling Plan, Operator Connect and Direct Routing support user phone numbers, Audio Conferencing numbers and voice application numbers such as auto attendants and call queues, while Teams Phone Mobile supports user phone numbers only and does not support Audio Conferencing or voice application numbers. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options > Note following the four bullets. Checked 2026-09-16.
[^83]: The billing telephone number given on a port request must match what the current service provider has on file and any account freeze must be removed, otherwise the port request is rejected after submission. Source: [Transfer phone numbers to Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/phone-number-calling-plans/transfer-phone-numbers-to-teams), Porting wizard - New (U.S. & Canada) > Billing telephone number (BTN). Checked 2026-09-21.
[^84]: Microsoft acknowledges confirmation of a submitted port request within 72 business hours, and order status is tracked in Teams admin center under Voice > Phone numbers > Order history. Source: [Transfer phone numbers to Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/phone-number-calling-plans/transfer-phone-numbers-to-teams), Porting wizard - New (U.S. & Canada) > Confirmation. Checked 2026-09-21.
[^85]: When numbers are ported into Calling Plans from Direct Routing or Operator Connect, preassignment is not allowed: in the United States and Canada the existing assignment can be maintained provided a Calling Plan licence and emergency location are in place before port completion, and outside the United States and Canada the numbers transfer in unassigned. Source: [Transfer phone numbers to Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/phone-number-calling-plans/transfer-phone-numbers-to-teams), What's the status of your port orders? table, Approved (FOCAccepted) row. Checked 2026-09-21.
[^86]: Teams Phone has four PSTN connectivity models - Microsoft Teams Calling Plan, Operator Connect, Teams Phone Mobile and Direct Routing - and an organisation can equip a tenant with as many of them as it wants and mix them per user population. Source: [PSTN connectivity options](https://learn.microsoft.com/en-us/microsoftteams/pstn-connectivity), PSTN connectivity options > 'The highlights of the four PSTN connectivity models for Teams are as follows'. Checked 2026-09-16.
[^87]: A PSTN solution is separate from a Teams Phone licence: the PSTN solution provides the tenant with phone numbers and PSTN access to domestic, international and emergency calling, while the Teams Phone licence entitles a user to enhanced calling capabilities in the tenant and access to that PSTN solution. Source: [What is Teams Phone](https://learn.microsoft.com/en-us/microsoftteams/what-is-phone-system-in-office-365), What is Teams Phone > Note. Checked 2026-09-16.
[^88]: The PowerShell chain for Direct Routing call routing is Set-CsOnlinePstnUsage to create a usage, New-CsOnlineVoiceRoute with -NumberPattern, -OnlinePstnGatewayList, -Priority and -OnlinePstnUsages, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy to assign it to a user. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Configuration steps > Using PowerShell, steps 1 to 4. Checked 2026-09-21.
[^89]: If a called number contains an extension the voice route number pattern is applied only to the number without the extension. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Voice routing policy considerations, Caution item 2. Checked 2026-09-21.
[^90]: Direct Routing call routing is built from four elements: an online voice routing policy that contains PSTN usages, PSTN usages that contain voice routes, voice routes that pair a number pattern with a set of online PSTN gateways, and the online PSTN gateway that points at an SBC. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Call routing overview, element list. Checked 2026-09-21.
[^91]: If the global (Org-wide default) online voice routing policy is configured and applied, every voice-enabled user in the organisation inherits it, which can send Calling Plan and Operator Connect users' PSTN calls to a Direct Routing trunk inadvertently. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Voice routing policy considerations, Caution item 1. Checked 2026-09-21.
[^92]: When an incoming PSTN call is forwarded or transferred and the ingress SBC is also a potential egress SBC, its priority value is ignored and it is prioritised above the other SBCs. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Voice routing with one PSTN usage, Note after the three-route summary table. Checked 2026-09-21.
[^93]: For a user with only a Teams Phone licence, a call whose dialled number matches none of the administrator-created voice route patterns is dropped; only a user who also holds a Microsoft Calling Plan licence falls back to the Calling Plan route automatically. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Voice routing with one PSTN usage, Note after the third-route diagram. Checked 2026-09-21.
[^94]: Voice routes are tried in priority order but the SBCs listed within a single route are tried in random order. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Voice routing with one PSTN usage, sentence after Call Flow 2. Checked 2026-09-21.
[^95]: Microsoft 365 admins can run a tenant self-diagnostics test that verifies a user is correctly configured for Direct Routing, and this feature is not available for Microsoft 365 Government, 21Vianet or Germany. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Run a Self-diagnostics tool. Checked 2026-09-21.
[^96]: The order of PSTN usages inside a voice routing policy is critical because usages are applied in order and if a match is found in the first usage the later usages are never evaluated; the order is changed with Set-CsOnlineVoiceRoutingPolicy. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 2: Voice routing with multiple PSTN usages, Note after the routing table. Checked 2026-09-21.
[^97]: If the tenant uses Continuous Access Evaluation tokens, the SBA is operational only for about 30 minutes because of the nature of continuous access evaluation, and an alternative is to disable CAE for the tenant. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations > Continuous Access Evaluation bullet. Checked 2026-09-16.
[^98]: SBA is supported on Teams Windows desktop, Teams macOS desktop and Teams Phones, and SBA mode activates only on desktop clients on a physical machine - VMs and web clients are not supported. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Supported Teams clients and How it works > SBA mode activation paragraph. Checked 2026-09-16.
[^99]: All Direct Routing SBA configuration is done with Teams PowerShell cmdlets - New-CsTeamsSurvivableBranchAppliance, New-CsTeamsSurvivableBranchAppliancePolicy, Set-CsTeamsSurvivableBranchAppliancePolicy and Grant-CsTeamsSurvivableBranchAppliancePolicy - plus an application registered in Microsoft Entra ID, and the Teams admin center does not yet support the feature. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), How it works > Configuration and its subsections; Register an application for the SBA with Microsoft Entra ID. Checked 2026-09-16.
[^100]: The Survivable Branch Appliance is distributable code provided by Microsoft to SBC vendors, who embed it in firmware or distribute it separately to run on a separate VM or hardware. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Direct Routing SBA > Prerequisites, first paragraph. Checked 2026-09-16.
[^101]: In SBA mode, sharing location information during an emergency call is not supported: users can still make the emergency call but location information will not be shared, and the only UI indicator that the client has switched to Appliance mode is a banner. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations > In SBA mode, the following user actions aren't supported. Checked 2026-09-16.
[^102]: SBA does not support Emergency Call Routing Policies; EMER dial strings bypass normalization and are always sent without a leading plus, so if the customer has no pattern in their regular voice routing policy matching the EMER dial strings, emergency calls fail via SBA. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Known issues and considerations > In SBA mode, the following user actions aren't supported. Checked 2026-09-16.
[^103]: While offline in SBA mode, a Teams client can make and receive PSTN calls through the local SBA and SBC, hold and resume, blind transfer, forward calls to a single number or Teams user, redirect an incoming PSTN call to a call queue or auto attendant number, fall back to PSTN when a VoIP call cannot be initiated, and make VoIP calls between two users registered behind the same SBA. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), How it works > When the Microsoft Teams client is in offline mode, the following calling-related functionality is available. Checked 2026-09-16.
[^104]: SBA prerequisites include the SBC being configured for Media Bypass, TLS 1.2 enabled on the SBA VM OS, and firewall openings for ports 3443, 4444 and 8443 (SBA server to Teams client), port 5061 (SBA server to SBC), UDP 123 for NTP and port 443 for Microsoft 365. Source: [Survivable Branch Appliance for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-survivable-branch-appliance), Direct Routing SBA > Prerequisites, bullet list. Checked 2026-09-16.
[^105]: Microsoft certifies and supports three emergency services providers for Direct Routing - Bandwidth Dynamic Location Routing, Intrado Emergency Routing Service and Inteliquent - and may reject support cases if a non-certified provider is used. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table footnote '*' - 911 service providers. Checked 2026-09-16.
[^106]: When MaxConcurrentSessions is set the alerting system notifies the administrator at 90 percent or more of that value, and when it is not set no alerts are generated although the monitoring system still reports concurrent sessions every 24 hours. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, 'Concurrent call capacity' row. Checked 2026-09-21.
[^107]: The SBC certificate should carry the SBC FQDN as Common Name or Subject Alternative Name, be signed by a Certificate Authority in the Microsoft Trusted Root Program and include the Server Authentication EKU, and wildcard certificates are supported when they comply with RFC 2818. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Public trusted certificate for the SBC. Checked 2026-09-21.
[^108]: Besides the domain being registered in the tenant, a user with that domain and an assigned E3 or E5 licence must exist, and the domain's configured authentication type must be Managed, otherwise pairing fails with a domain-not-configured error. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, second and third bullets. Checked 2026-09-21.
[^109]: The trunk failover defaults are response codes 408, 503 and 504 and a FailoverTimeSeconds of 10 seconds, after which an unanswered outbound call is routed to the next available trunk or dropped if none exists. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, 'Failover response codes' and 'Failover times (seconds)' rows. Checked 2026-09-21.
[^110]: ForwardCallHistory and ForwardPai both default to False; turning on call history makes Microsoft 365 send History-Info and Referred-By headers, and turning on PAI also sends the Privacy:ID header. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, 'Forward call history' and 'Forward P-Asserted-identity (PAI) header' rows. Checked 2026-09-21.
[^111]: An SBC can only be paired if the domain portion of its FQDN matches a domain registered in the tenant, and *.onmicrosoft.com domain names are not supported for the SBC FQDN. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, second bullet. Checked 2026-09-21.
[^112]: New-CsOnlinePSTNGateway has an IPAddressVersion option of IPv4 or IPv6, and when IPv6 is set the SBC must use IPv6 for both signalling and media, with media bypass unsupported and mixed IPv6/IPv4 SIP and media unsupported. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, IPAddressVersion bullet. Checked 2026-09-21.
[^113]: The certified SBC page repeats that media re-targeting isn't supported: if the SBC sends a new media IP during a Direct Routing call it is negotiated in signalling but Teams never sends media to the new address. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Session Border Controllers certified for Direct Routing > final Note. Checked 2026-09-16.
[^114]: The certified SBC page states that Microsoft is not accepting new nominations for SBC certification until further notice. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Session Border Controllers certified for Direct Routing > sentence below the intro. Checked 2026-09-16.
[^115]: SIP OPTIONS pings must not exceed a frequency of one transaction every 60 seconds and must not be more or less frequent than one transaction every 180 seconds for each configured trunk for each endpoint. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, SIP OPTIONS bullet. Checked 2026-09-21.
[^116]: An SBC is paired to Direct Routing with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true as the minimum parameters. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant, first code block. Checked 2026-09-21.
[^117]: SendSIPOptions defaults to True and Microsoft highly recommends leaving it on, because when it is off the SBC is excluded from the Monitoring and Alert system. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, 'Send SIP options' row. Checked 2026-09-21.
[^118]: Multiple IP addresses mapped to the same FQDN on the SBC side are not supported for Direct Routing. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, fourth bullet. Checked 2026-09-21.
[^119]: An SBC can be connected either in the Microsoft Teams admin center or with PowerShell, but for GCC High and DoD clouds PowerShell must be used because the admin center option is not available. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Introduction, Note immediately before 'Use the Microsoft Teams admin center'. Checked 2026-09-21.
[^120]: Microsoft forces TLS 1.2 on the Direct Routing SIP interface and the SBC must be able to connect with one of four ECDHE-RSA cipher suites using AES 128 or 256 in GCM or CBC mode. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, TLS bullet. Checked 2026-09-21.
[^121]: Microsoft requires that Direct Routing issues be raised with the SBC vendor's customer support first, with the vendor escalating to Microsoft through internal channels, and customers must present an SBC vendor investigation report when opening a Microsoft support request. Source: [Configure Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-configure), Configure Direct Routing > Support Boundaries. Checked 2026-09-16.
[^122]: Pairing is verified by running Get-CsOnlinePSTNGateway and confirming the SBC appears with Enabled set to True, and by confirming in the SBC management interface that outgoing OPTIONS receive 200 OK and that the SBC answers incoming OPTIONS from Direct Routing with 200 OK. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Verify the SBC connection > Check whether the SBC is on the list of paired SBCs; Validate SIP options. Checked 2026-09-21.
[^123]: Microsoft directs the SBC to the nearest healthy datacentre and redirects to the secondary and then tertiary region if the primary is unavailable, with no manual administrator intervention required. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling failover. Checked 2026-09-21.
[^124]: Cisco ATA191-MPP and ATA192-MPP carry footnote marker 3 in the compatible devices table, whose definition is that the device supports only static location with SIP Gateway (inferred). Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Compatible devices table > ATA191-MPP and ATA192-MPP rows, Remarks/footnote column; footnote 3 definition. Checked 2026-09-16.
[^125]: SIP Gateway automatically offboards stale devices provisioned for a tenant: paired devices not connected for 30 days, and unpaired devices after 14 days; an offboarded device can be onboarded again after a factory reset. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Benefits of SIP Gateway > Off board stale devices. Checked 2026-09-16.
[^126]: Compatible Cisco SIP IP phones support dynamic location discovery over LLDP only, and the page's footnote markers show the Cisco MPP phones and the ATA191/192-MPP as supporting dynamic location discovery through LLDP. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Plan SIP Gateway > notes under the Compatible devices table, and the ^1^/^2^/^3^ footnote definitions. Checked 2026-09-16.
[^127]: For Cisco, devices running enterprise firmware must be converted to multiplatform firmware, and the compatible table lists 6821, 6841, 6851, 6861, 6871, 7811, 7821, 7841, 7861, 8811, 8841, 8845, 8851, 8861, 8865 and 8832 with minimum 11.1.1MPP and approved 12-0-7MPP, ATA191-MPP and ATA192-MPP at minimum 11.2.2MPP and approved 11-3-1MPP, and 8875 plus the 9841/9851/9861/9871 at PhoneOS 3.3.1. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Plan SIP Gateway > Compatible devices > Cisco rows. Checked 2026-09-16.
[^128]: SIP Gateway lets an organisation use any compatible SIP device with Microsoft Teams, including Skype for Business IP phones with standard SIP firmware, Cisco IP phones with multiplatform SIP firmware, and SIP devices from Poly, Yealink and AudioCodes. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Plan SIP Gateway > opening paragraph. Checked 2026-09-16.
[^129]: Customers can use SIP devices as call queue agents with restrictions, for instance SIP Gateway does not publish presence for devices so presence-based routing is not supported. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Benefits of SIP Gateway > Call Queues and voice apps support. Checked 2026-09-16.
[^130]: Teams users must have a phone number with PSTN calling enabled to use SIP Gateway, and SIP Gateway is not yet available for DoD. Source: [Plan SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-plan), Plan SIP Gateway > Requirements to use SIP Gateway and its following Note. Checked 2026-09-16.
[^131]: Direct Routing SIP/TLS signalling from the SBC to the Microsoft SIP proxy uses destination port 5061, while traffic from the Microsoft SIP proxy to the SBC uses the port configured on the SBC. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling ports table. Checked 2026-09-21.
[^132]: Bulk sign-in of SIP devices works in batches of up to 100 devices with at most three concurrent batches per region, requires the site public IP to have been a trusted IP for at least 24 hours, the tenant ID in the provisioning URL, Teams PowerShell 5.6.0 or later, accounts without MFA that hold a phone number, the CommonAreaPhone policy and AllowSIPDevicesCalling. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Bulk sign in > Bulk sign in prerequisites. Checked 2026-09-21.
[^133]: SIP Gateway is enabled for users through a Teams calling policy, either with the 'SIP devices can be used for calls' setting in Teams admin center or Set-CsTeamsCallingPolicy -AllowSIPDevicesCalling True, the default being False, and policy propagation may take up to 24 hours. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Enable SIP Gateway for the users in your organization > By using PowerShell. Checked 2026-09-21.
[^134]: Every SIP device must be reset to factory default settings before it is used with SIP Gateway, and only compatible SIP devices can be onboarded. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Before you can configure SIP Gateway, do the following, first bullet. Checked 2026-09-21.
[^135]: SIP Gateway requires outbound-only firewall openings of UDP ports 49152 to 53247 and TCP port 5061 towards IP ranges 52.112.0.0/14 and 52.122.0.0/15, the devices must not sit behind an HTTP proxy, and SIP Gateway supports IPv4 only. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Before you can configure SIP Gateway, do the following; and Microsoft Teams and IPv6. Checked 2026-09-21.
[^136]: SIP Gateway provisioning server URLs are regional - emea.ipp.sdg.teams.microsoft.com, noam.ipp.sdg.teams.microsoft.com and apac.ipp.sdg.teams.microsoft.com - and for Cisco devices the URL must have /$PSN.xml appended and is delivered with DHCP option 160. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Set the SIP Gateway provisioning server URL > Using DHCP, and the Note following it. Checked 2026-09-21.
[^137]: SIP Gateway falls back to emergency calling based on registered addresses for devices that do not share location attributes, and registered addresses are not currently supported for Direct Routing scenarios. Source: [Configure SIP Gateway](https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure), Emergency calling. Checked 2026-09-21.
[^138]: Teams Phone is Microsoft's technology for enabling call control and Private Branch Exchange (PBX) capabilities in the Microsoft 365 cloud, and Microsoft states it allows replacing an existing PBX system. Source: [What is Teams Phone](https://learn.microsoft.com/en-us/microsoftteams/what-is-phone-system-in-office-365), What is Teams Phone > opening paragraph and 'Teams Phone allows you to replace your existing PBX system...'. Checked 2026-09-16.
[^139]: Translation rules are created with New-CsTeamsTranslationRule and attached to a gateway with New-CsOnlinePSTNGateway or Set-CsOnlinePSTNGateway through the InboundTeamsNumberTranslationRules, InboundPSTNNumberTranslationRules, OutboundTeamsNumberTranslationRules and OutboundPSTNNumberTranslationRules parameters. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Considerations > Configuring translation rules with PowerShell. Checked 2026-09-21.
[^140]: Inbound Direct Routing calls are matched to a Teams user or resource account by Reverse Number Lookup on the dialled number-string, so where the SBC passes through a format that does not match the assigned number-string an inbound translation rule on the gateway is needed. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Route-based number translations - for inbound calls. Checked 2026-09-21.
[^141]: The maximum total number of translation rules is 400, the maximum parameter-name length is 100 symbols, the maximum pattern length is 1024 symbols and the maximum translation length is 256 symbols. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Considerations, Note listing the maximums. Checked 2026-09-21.
[^142]: Number translation rules are applied at the SBC level, multiple rules can be assigned to one SBC and they are applied in the order in which they appear when listed in PowerShell. Source: [Translate phone numbers for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-translate-numbers), Considerations, first paragraph. Checked 2026-09-21.
[^143]: Cloud Voicemail configuration for a Direct Routing user is automatic and requires no other configuration once the licence and number are in place. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice, opening paragraph. Checked 2026-09-21.
[^144]: Microsoft recommends, but does not require, that a Direct Routing phone number is configured as a full E.164 number with country code. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice > Use PowerShell, recommendation paragraph. Checked 2026-09-21.
[^145]: Phone numbers can be configured with extensions so several users share one base number, and for the lookup to succeed the INVITE must contain the full number with the extension, for example sip:+14255388701;ext=1001. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice > Use PowerShell, paragraph after the extension examples. Checked 2026-09-21.
[^146]: Direct Routing requires the user to be homed online, which is checked by confirming RegistrarPool has a value in the infra.lync.com domain; where OnPremLineUri is populated the number was assigned on-premises and must be cleared with Set-CsUser -LineUri $null in the Skype for Business Management Shell and synchronised before the number is configured online. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Ensure that the user is homed online. Checked 2026-09-21.
[^147]: A Direct Routing number is assigned with Set-CsPhoneNumberAssignment using -PhoneNumber and -PhoneNumberType DirectRouting, and that command automatically enables the user for Enterprise Voice. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice > Use PowerShell, second bullet. Checked 2026-09-21.
[^148]: Uploading Direct Routing numbers into Microsoft's telephone number management inventory is optional, and assigning a number to a user automatically uploads it if it is not already there. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Upload Direct Routing numbers to your tenant, introductory paragraphs. Checked 2026-09-21.
[^149]: Direct Routing numbers are uploaded in bulk with New-CsOnlineDirectRoutingTelephoneNumberUploadOrder using -FileContent, each request supports up to 10,000 telephone numbers, and the upload is asynchronous. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Upload Direct Routing numbers to your tenant > Use PowerShell. Checked 2026-09-21.
[^150]: Direct Routing requires users to be in Teams Only mode so that incoming calls land in the Teams client, which is done by assigning the UpgradeToTeams instance of TeamsUpgradePolicy. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Assign Teams Only mode to users to ensure calls land in Microsoft Teams. Checked 2026-09-21.
[^151]: Attaching opaque=app:voicemail to the Request-URI sends a Direct Routing call straight to the user's voicemail without ringing the Teams client. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure sending calls directly to voicemail. Checked 2026-09-21.
[^152]: Call queue exception handling can redirect calls to people, voicemail, other call queues or auto attendants when no agents are signed in, when the number of waiting callers exceeds a configured limit, or when a caller's wait time exceeds a configured limit. Source: [Planning - Overview of voice applications](https://learn.microsoft.com/en-us/microsoftteams/aa-cq-plan-overview), Call Queue, exception handling list. Checked 2026-09-21.
[^153]: Call queues do not provide separate call routing for off hours and holidays, and Microsoft recommends using an auto attendant in front of the queue to direct calls even where the queue is staffed around the clock. Source: [Planning - Overview of voice applications](https://learn.microsoft.com/en-us/microsoftteams/aa-cq-plan-overview), Call Queue, closing paragraph. Checked 2026-09-21.
[^154]: Internal Teams callers reach an auto attendant or call queue by calling its resource account, while external callers reach it by dialling the phone number assigned to that resource account. Source: [Planning - Overview of voice applications](https://learn.microsoft.com/en-us/microsoftteams/aa-cq-plan-overview), Auto Attendant, final paragraph; Call Queue, final paragraph. Checked 2026-09-21.
[^155]: The end of software maintenance releases for Version 14 perpetual on-premises calling applications was 7 April 2026, meaning Cisco may no longer issue maintenance or bug-fix builds for that release. Source: [End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual](https://www.cisco.com/c/en/us/products/collateral/unified-communications/unified-communications-manager-callmanager/v-14-premises-calling-applications-eol.html), Milestone table, End of SW Maintenance Releases Date. Checked 2026-09-04.
[^156]: The last date of support for Version 14 perpetual on-premises calling applications is 30 April 2027, after which Cisco states all support services are unavailable and the product is obsolete. Source: [End-of-Sale and End-of-Life Announcement for the Cisco Version 14 of On-premises Calling applications (including Cisco Unified Communications Manager) — Perpetual](https://www.cisco.com/c/en/us/products/collateral/unified-communications/unified-communications-manager-callmanager/v-14-premises-calling-applications-eol.html), Milestone table, Last Date of Support. Checked 2026-09-04.
