# Setting up Microsoft Teams Direct Routing

Systems: Microsoft Teams Phone

For Teams voice administrators and partner engineers configuring Session Border Controller pairing and voice routing.

Canonical: https://warmtransfer.net/guides/teams-direct-routing-setup

Last verified: 2026-09-24

Microsoft Teams Phone Direct Routing connects customer telephony infrastructure to Teams through a supported, customer-provided Session Border Controller (SBC)[^65]. Microsoft supports Teams Phone with Direct Routing only when Microsoft-certified SBCs are used[^46].

## Before you start

Direct Routing requires a Microsoft-certified SBC, telephony trunks, a Microsoft 365 tenant with online users, a verified domain, a public IP address and DNS record for the SBC FQDN, a public certificate, and permitted signaling and media network paths[^66]. Users require Microsoft Teams and Teams Phone licenses and must be homed online[^60][^59]. Direct Routing is not supported in Teams Islands mode[^67].

## What changes by situation

- Which certified Session Border Controller family are you connecting? AudioCodes Mediant SBC; Ribbon SBC Core or Edge; Oracle Acme Packet; Cisco Unified Border Element; Another certified SBC product.
- How will media flow between Teams clients and the SBC? No media bypass: all media flows through Media Processors; Media bypass on a second trunk FQDN for pilot users first; Media bypass enabled directly on the primary trunk.

## Step 1: Verify certified SBC model and firmware

**AudioCodes Mediant SBC**

### Do
Verify that the Mediant SBC model (AudioCodes Mediant 500, 800, 1000B, 2600, 3100, 4000, 9000, Virtual Edition, or Cloud Edition) is running supported firmware 7.40A.600 or recommended firmware 7.40A.500[^12]. Firmware higher than the documented version is supported as long as the major.minor version is the same[^15]. For Direct Routing issues, contact the SBC vendor first[^52].

### Verify
Confirm that the running firmware on the SBC matches the 7.40A train[^15][^12].

### Rollback
Suggested rollback: No configuration was altered on the SBC during firmware verification.

**Ribbon SBC Core or Edge**

### Do
Verify that the SBC release is 11.1 or later, 10.1, 9.2, or 7.2 for Ribbon SBC 5400, SBC 7000, and SBC SWe, or 12.x or later, 11.x, or 9.x for Ribbon SBC 1000, SBC 2000, and SBC SWe Edge[^17]. Firmware higher than documented is supported within the same major.minor version[^15]. For Direct Routing issues, contact the SBC vendor first[^52].

### Verify
Confirm that the running release matches one of the supported release trains[^17].

### Rollback
Suggested rollback: No configuration was altered on the SBC during firmware verification.

**Oracle Acme Packet**

### Do
Verify that the platform runs 9.x or 10.x for Oracle AP 1100, AP 3900, AP 3950, AP 4600, AP 4900, AP 6350, and VME; AP 6300 is supported on 9.x and AP 6400 on 10.x[^16]. Higher firmware is supported within the same major.minor release[^15]. For Direct Routing issues, contact the SBC vendor first[^52].

### Verify
Confirm that the running platform firmware matches the listed major.minor train[^16][^15].

### Rollback
Suggested rollback: No configuration was altered on the SBC during firmware verification.

**Cisco Unified Border Element**

### Do
Verify that the Cisco Unified Border Element runs supported IOS XE Amsterdam 17.2.1r or later on ISR 1000, ISR 4000, CSR 1000V, and ASR 1000, or 17.3.2 or later on Catalyst 8000 Edge[^14]. Cisco recommends release 17.6.1a, or 17.3.3 on CSR 1000V[^14]. Higher releases are supported within the same major.minor[^15]. For Direct Routing issues, contact the SBC vendor first[^52].

### Verify
Confirm that the installed IOS XE version meets or exceeds the required minimum release[^14].

### Rollback
Suggested rollback: No configuration was altered on the router during firmware verification.

**Another certified SBC product**

### Do
Locate the exact product entry in Microsoft's certified SBC table and verify its supported firmware major.minor train[^15]. Verify whether the product is certified for media bypass, noting that products such as Thinktel Think 365 SBC, Patton SmartNode eSBC, Frafos ABC SBC, and Vodia PBX are certified without media bypass[^13]. For Direct Routing issues, contact the SBC vendor first[^52].

### Verify
Confirm that the running SBC firmware matches the documented certified major.minor release[^15].

### Rollback
Suggested rollback: No configuration was altered on the SBC during firmware verification.

## Step 2: Prepare the SBC domain in the Microsoft 365 tenant

**No media bypass: all media flows through Media Processors**

### Do
Select an SBC FQDN whose domain matches a domain registered in the tenant[^27]. The default *.onmicrosoft.com domain cannot be used[^27]. If the SBC FQDN uses a subdomain, register the subdomain in the tenant as well[^26]. Ensure that the domain's authentication type is set to Managed and that a user in that domain is assigned an E3 or E5 license[^22][^23].

### Verify
Confirm that the domain is verified in the tenant and that a licensed user exists with a UPN in that domain[^22].

### Rollback
Suggested rollback: Remove the domain only after unpairing the SBC.

**Media bypass on a second trunk FQDN for pilot users first**

### Do
Select a primary SBC FQDN and plan a distinct secondary trunk FQDN on the same SBC[^27][^9]. Register the domain and any subdomains for both FQDNs in the tenant[^27][^26]. The default *.onmicrosoft.com domain cannot be used[^27]. Ensure that the authentication type for the domain is Managed and that a user in the domain holds an E3 or E5 license[^22][^23].

### Verify
Confirm that both FQDN domains are verified in the tenant and that a licensed user exists in the registered domain[^22].

### Rollback
Suggested rollback: Remove the domains only after unpairing the SBC trunks.

**Media bypass enabled directly on the primary trunk**

### Do
Select an SBC FQDN whose domain matches a verified tenant domain, excluding *.onmicrosoft.com domains[^27]. Register any intermediate subdomains in the tenant[^26]. Set the domain authentication type to Managed and assign an E3 or E5 license to a user in that domain[^22][^23].

### Verify
Confirm that the domain is registered and that an active user in the domain holds an E3 or E5 license[^22].

### Rollback
Suggested rollback: Remove the domain only after unpairing the SBC.

## Step 3: Install the public TLS certificate on the SBC

**No media bypass: all media flows through Media Processors**

### Do
Generate a Certificate Signing Request (CSR) on the SBC[^54]. Obtain a certificate carrying the SBC FQDN as Common Name (CN) or Subject Alternative Name (SAN), signed by a CA in the Microsoft Trusted Root Program and including the Server Authentication EKU[^54]. A wildcard certificate adhering to RFC 2818 is supported[^55]. Install the certificate and root chain on the SBC[^54].

### Verify
Confirm that the installed certificate includes the SBC FQDN and that the health dashboard shows no certificate expiration warning[^30].

### Rollback
Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

**Media bypass on a second trunk FQDN for pilot users first**

### Do
Generate a CSR on the SBC[^54]. Obtain a public certificate covering both trunk FQDNs—either with both names listed in the SAN or via an RFC 2818 wildcard—signed by a Microsoft Trusted Root Program CA and containing the Server Authentication EKU[^54][^3][^55]. Install the certificate chain on the SBC[^54].

### Verify
Confirm that both the primary and phased bypass trunk FQDNs match the SAN entries or wildcard scope[^3].

### Rollback
Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

**Media bypass enabled directly on the primary trunk**

### Do
Generate a CSR on the SBC and obtain a public certificate issued by a CA in the Microsoft Trusted Root Program with Server Authentication EKU, covering the SBC FQDN in the CN or SAN (or RFC 2818 wildcard)[^54][^55]. Install the certificate on the SBC[^54].

### Verify
Confirm that the SBC FQDN is covered by the certificate and that the health dashboard indicates valid TLS connectivity[^30].

### Rollback
Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

## Step 4: Configure DNS records and firewall rules

**No media bypass: all media flows through Media Processors**

### Do
Publish a public DNS record mapping the SBC FQDN to the SBC's public IP address[^33]. Configure perimeter firewalls to permit outbound SIP/TLS from the SBC to destination port 5061 across 52.112.0.0/14 and 52.120.0.0/14[^51][^50]. Permit inbound SIP/TLS from 52.112.0.0/14 and 52.120.0.0/14 to the SBC's configured signaling port[^51][^50]. Permit bidirectional UDP/SRTP media between the SBC and Microsoft Media Processors on ports 3478 to 3481 and 49152 to 53247[^34].

### Verify
Confirm that DNS resolves the SBC FQDN to the public IP address and that the SBC receives 200 OK to outgoing OPTIONS[^33][^63].

### Rollback
Suggested rollback: Remove the created firewall access control rules and delete the public DNS record.

**Media bypass on a second trunk FQDN for pilot users first**

### Do
Publish public DNS records for both trunk FQDNs to the SBC public IP[^33]. Open outbound SIP/TLS to port 5061 and inbound SIP/TLS across 52.112.0.0/14 and 52.120.0.0/14 for both distinct signaling ports[^51][^50][^9]. Permit bidirectional Media Processor UDP/SRTP ports 3478 to 3481 and 49152 to 53247[^34][^6]. Permit client-to-SBC UDP/SRTP from client ports 50000 to 50019 to the SBC public IP and media ports[^4]. Allow Transport Relay traffic across 52.112.0.0/14 with relay source ports 50000 to 59999 and SBC-to-relay destination ports 50000 to 59999 and 3478 to 3481[^11].

### Verify
Confirm that both signaling ports receive SIP OPTIONS traffic and negotiate 200 OK responses[^63].

### Rollback
Suggested rollback: Remove the bypass and secondary signaling firewall rules and unpublish the DNS records.

**Media bypass enabled directly on the primary trunk**

### Do
Publish a public DNS record pointing the SBC FQDN to the public IP[^33]. Open SIP/TLS on destination port 5061 and the SBC signaling port across 52.112.0.0/14 and 52.120.0.0/14[^51][^50]. Permit bidirectional Media Processor UDP/SRTP ports 3478 to 3481 and 49152 to 53247[^34][^6]. Allow client UDP/SRTP from client ports 50000 to 50019 to the SBC media ports, and Transport Relay traffic on 52.112.0.0/14 with relay source ports 50000 to 59999 and destination ports 50000 to 59999 and 3478 to 3481[^4][^11].

### Verify
Confirm that DNS resolves the FQDN and that SIP signaling connects over the configured port[^33][^63].

### Rollback
Suggested rollback: Remove the bypass firewall rules and delete the public DNS record.

## Step 5: Configure the SBC SIP trunk interface

### Do
Configure the SBC trunk to enforce TLS 1.2 with at least 1 supported ECDHE-RSA cipher suite: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256[^56]. For Microsoft 365, Office 365, and GCC tenants, point the SIP trunk toward Microsoft connection endpoints in priority order: `sip.pstnhub.microsoft.com`, `sip2.pstnhub.microsoft.com`, and `sip3.pstnhub.microsoft.com`[^49]. Configure the SBC to send SIP OPTIONS pings to Microsoft, populating the Contact header with the SBC FQDN[^36][^63].

### Verify
Review the SBC SIP logs to confirm successful TLS establishment and outbound SIP OPTIONS transmission[^63]. If messages are rejected, inspect SBC logs directly because Call Analytics does not report pairing failures[^47].

### Rollback
Suggested rollback: Disable or remove the SIP trunk entity and reset TLS profiles on the SBC interface.

## Step 6: Pair the SBC with the tenant

### Do
Pair the SBC in the Microsoft Teams admin center under Voice > Direct Routing > SBCs > Add, or execute New-CsOnlinePSTNGateway with -Fqdn, -SipSignalingPort, -MaxConcurrentSessions, and -Enabled $true[^37]. Leave Send SIP options enabled to avoid excluding the SBC from the monitoring system[^48].

### Verify
If pairing rejects with an error that the domain was not configured for this tenant, verify the licensed user and domain configuration[^22].

### Rollback
To suspend calling during maintenance, set Enabled to False[^24]. To remove the gateway, remove it from all voice routes before executing Remove-CsOnlinePSTNGateway[^42].

## Step 7: Verify gateway status and health metrics

### Do
Execute Get-CsOnlinePSTNGateway -Identity <FQDN> and inspect the SBC status in the Teams admin center under Voice > Direct Routing[^62][^30]. Check SBC logs to verify reciprocal 200 OK responses for SIP OPTIONS messages in both directions[^63].

### Verify
Confirm that Enabled reflects True[^62]. Confirm that the health dashboard displays SIP options status as Active and shows no TLS connectivity warnings[^30].

### Rollback
Suggested rollback: No configuration was altered during this verification step.

## Step 8: Configure PSTN usages and voice routes

### Do
Create a PSTN usage record using Set-CsOnlinePstnUsage -Identity Global -Usage @{Add="<name>"} or in the Teams admin center under Voice > Direct Routing > Manage PSTN usage records[^41]. Create voice routes using New-CsOnlineVoiceRoute with -Identity, -NumberPattern, -OnlinePstnGatewayList, -Priority, and -OnlinePstnUsages[^64]. If multiple SBCs are listed in a route, note that Teams attempts them in random order[^44].

### Verify
Run (Get-CsOnlinePSTNUsage).Usage to verify that the usage appears, and run Get-CsOnlineVoiceRoute to confirm pattern, gateway list, and priority settings[^41][^64].

### Rollback
Delete unnecessary routes using Remove-CsOnlineVoiceRoute, which leaves existing policies intact and only stops matching traffic for that route pattern[^43].

## Step 9: Configure tenant dial plans

### Do
Create dial plans using New-CsTenantDialPlan[^19]. Define normalization rules that output numbers beginning with a leading +, ordering rules top down[^20][^21]. If the SBC requires dialing without a +, use trunk translation rules rather than stripped dial plan rules[^21].

### Verify
Test normalization by running Test-CsEffectiveTenantDialPlan -DialedNumber <digits> -Identity <user> to ensure translated numbers match intended voice route patterns[^19][^35].

### Rollback
Remove the dial plan using Remove-CsTenantDialPlan -Identity <name>[^19].

## Step 10: Create online voice routing policies

### Do
Create custom voice routing policies using New-CsOnlineVoiceRoutingPolicy <name> -OnlinePstnUsages <usages>[^38]. Sequence PSTN usages so that evaluation stops at the first matching usage[^58]. Avoid assigning Direct Routing usages directly to the Global policy unless every user in the tenant must inherit them[^29].

### Verify
Confirm the order of OnlinePstnUsages on the policy, using Set-CsOnlineVoiceRoutingPolicy -OnlinePstnUsages @{Replace=...} to correct the sequence if needed[^58].

### Rollback
Suggested rollback: Remove the custom voice routing policy after unassigning it from all pilot accounts.

## Step 11: Enable pilot user accounts

### Do
Verify that pilot users have Microsoft Teams and Teams Phone licenses, are homed online, and are assigned Teams Only mode[^60][^59][^53]. Assign the phone number with Set-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting, which automatically enables Enterprise Voice[^1]. Assign the voice routing policy using Grant-CsOnlineVoiceRoutingPolicy -Identity <user> -PolicyName <name>[^38].

### Verify
Run Get-CsOnlineUser <user> | select OnlineVoiceRoutingPolicy, RegistrarPool to verify that the policy is applied and RegistrarPool resides within infra.lync.com[^38][^59].

### Rollback
Unassign the policy with Grant-CsOnlineVoiceRoutingPolicy -Identity <user> -PolicyName $null to return to Global policy governance[^40]. Remove the phone number assignment using Remove-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting, which sets EnterpriseVoiceEnabled to False[^57].

## Step 12: Apply media bypass mode

**No media bypass: all media flows through Media Processors**

### Do
Leave media bypass disabled on the paired trunk[^8]. All media sessions flow through Microsoft Media Processors[^34].

### Verify
Confirm that Get-CsOnlinePSTNGateway -Identity <FQDN> displays MediaBypass set to False[^8].

### Rollback
Suggested rollback: No configuration change is required as media bypass remains disabled.

**Media bypass on a second trunk FQDN for pilot users first**

### Do
Configure the secondary trunk on the SBC according to vendor instructions[^10]. Pair the second FQDN using a different signaling port via New-CsOnlinePSTNGateway[^9][^37]. Enable media bypass on the secondary trunk by executing Set-CsOnlinePSTNGateway -Identity <second FQDN> -MediaBypass $true[^8]. Configure a dedicated voice route and voice routing policy referencing this gateway and assign it to pilot users[^9].

### Verify
Verify that the secondary trunk displays SIP options as Active in the health dashboard[^30]. Test pilot calls using desktop, mobile, or Teams Phone devices, noting that web endpoints automatically revert to non-bypass[^5].

### Rollback
Reassign pilot users to the non-bypass voice routing policy or run Set-CsOnlinePSTNGateway -Identity <second FQDN> -MediaBypass $false[^38][^8].

**Media bypass enabled directly on the primary trunk**

### Do
Configure media bypass parameters on the SBC per vendor guidelines[^10]. Enable media bypass across the trunk by executing Set-CsOnlinePSTNGateway -Identity <FQDN> -MediaBypass $true[^8]. Be aware that this immediately alters the media path for all production users on that trunk[^2].

### Verify
Confirm that MediaBypass reflects True in Get-CsOnlinePSTNGateway output and test calls on supported desktop or mobile clients[^8][^5].

### Rollback
Revert the trunk to non-bypass by executing Set-CsOnlinePSTNGateway -Identity <FQDN> -MediaBypass $false[^8].

## Step 13: Test calls and failover behavior

### Do
Conduct Microsoft's recommended post-configuration validations: inbound and outbound PSTN calling, emergency calling if configured, failover across SIP connection points, voice routing policy assignments, and call quality[^61]. Dial a number that does not match any route in the assigned policy; for a user without a Calling Plan license, the call must be dropped[^35].

### Verify
Confirm that calls succeed and that the Direct Routing health dashboard continues to report SIP options status as Active[^30]. If an SBC ceases sending OPTIONS, confirm that Direct Routing demotes it rather than routing to it first[^36].

### Rollback
Suggested rollback: If calls fail, review SBC SIP error logs and unassign pilot user policies to halt routing.

## See also

- [Microsoft Teams Phone](https://warmtransfer.net/knowledge/microsoft-teams-phone)
- [Teams Phone Direct Routing and SBC certification](https://warmtransfer.net/knowledge/teams-direct-routing)
- [Teams voice routing policies and dial plans](https://warmtransfer.net/knowledge/teams-voice-routing)
- [Microsoft Teams Phone architecture and licensing](https://warmtransfer.net/knowledge/teams-phone-architecture)
- [Teams Operator Connect and Azure Communication routing](https://warmtransfer.net/knowledge/teams-operator-connect)
- [Teams contact center integration models](https://warmtransfer.net/knowledge/teams-contact-center-integration)

## Applicability

Applies to: Microsoft Teams Phone, AudioCodes Mediant SBC, Cisco Unified Border Element, Oracle Acme Packet SBC, Ribbon Communications Ribbon SBC Core, MicrosoftTeams PowerShell module, and Microsoft Teams Phone Direct Routing. Deployments: multi-tenant, customer-managed-sbc, dod, and gcc-high. Sources checked 2026-09-24. In GCC High and DoD clouds, SBC pairing must be performed via PowerShell because the Teams admin center does not provide the pairing option[^28]. Direct Routing supports codecs SILK, G.711, G.722, and G.729, while AMR-WB is supported exclusively on non-bypass calls[^18]. Media bypass is unsupported when IPv6 is used for SIP or media[^7].

## What remains uncertain

Whether an administrator can confirm via Microsoft admin tools that a specific call successfully bypassed Media Processors is not covered by the sources below.

Vendor-specific SBC command-line and web interface configuration procedures beyond Microsoft-documented SIP parameters are not covered by the sources below.

## Sources

[^1]: When the number is managed online, Set-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting assigns the number and automatically enables Enterprise Voice, and the admin center equivalent is Users > Manage users > Account > Assign phone number with type Direct Routing. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Configure the phone number and enable enterprise voice (admin center and PowerShell). Checked 2026-09-24.
[^2]: Turning bypass on for an existing trunk switches all production users at the same time, and initial trunk or port issues may then affect production users, which is why Microsoft recommends the phased approach. Source: [Configure media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-configure-media-bypass), Migrate from non-bypassed trunks to bypass-enabled trunks, Switch all users at once bullet. Checked 2026-09-24.
[^3]: When two trunks share one SBC for a phased bypass migration, the certificate must support both trunks, either with both FQDNs in the SAN or with a wildcard certificate. Source: [Configure media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-configure-media-bypass), Migrate from non-bypassed trunks to bypass-enabled trunks, Phased approach bullet. Checked 2026-09-24.
[^4]: For direct bypass media the Teams client must reach the SBC's public IP address, with UDP/SRTP between client ports 50000 to 50019 and the media ports defined on the SBC. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Media traffic: IP and Port ranges > Requirements for direct media traffic. Checked 2026-09-24.
[^5]: Media bypass is supported on standalone Teams desktop clients, Android and iOS clients and Teams Phone devices, and calls on other endpoints such as Teams web clients and Skype for Business 3PIP phones are automatically converted to non-bypass. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Client endpoints supported with media bypass. Checked 2026-09-24.
[^6]: Even on a bypass trunk, Media Processors stay in the media path for voice applications such as Call Park, auto attendants and call queues, for web clients, and when a call escalates to a group call, goes to a federated Teams user or is transferred to a Skype for Business user. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Use of Media Processors and Transport Relays; Use of Teams Media Processors if trunk is configured for media bypass; Requirements for using media processors. Checked 2026-09-24.
[^7]: Media bypass is not supported when IPv6 is used for SIP or media or with the IPv6 Teams client, and mixed IPv6/IPv4 SIP and media is not supported. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations, IPAddressVersion bullet. Checked 2026-09-24.
[^8]: Media bypass is controlled per SBC with Set-CsOnlinePSTNGateway -Identity <FQDN> -MediaBypass set to $true or $false. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), About media bypass with Direct Routing, second paragraph. Checked 2026-09-24.
[^9]: Microsoft's recommended phased migration to media bypass creates a second trunk with a different FQDN on the same SBC, using a different TLS signaling port but the same media ports, and a separate online voice routing policy assigned to test users. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Configure separate trunks for media bypass and non-media bypass. Checked 2026-09-24.
[^10]: Turning on media bypass requires that the SBC vendor supports media bypass and provides SBC-side instructions, that bypass is turned on for the trunk, and that the required ports are opened. Source: [Configure media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-configure-media-bypass), Introduction, numbered conditions 1 to 3. Checked 2026-09-24.
[^11]: When bypass media flows through Teams Transport Relays (52.112.0.0/14 in commercial and GCC), relay-to-SBC traffic uses source ports 50000 to 59999 and SBC-to-relay traffic uses destination ports 50000 to 59999 and 3478 to 3481. Source: [Plan for media bypass with Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass), Media traffic: IP and Port ranges > Requirements for using Transport Relays. Checked 2026-09-24.
[^12]: AudioCodes Mediant 500, 800, 1000B, 2600, 3100, 4000, 9000, Virtual Edition and Cloud Edition SBCs are listed as certified for both non-bypass and media bypass with supported firmware 7.40A.600 and recommended 7.40A.500. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, AudioCodes rows. Checked 2026-09-24.
[^13]: The certified SBC table marks non-media-bypass and media-bypass certification separately per product, and some certified products, including Thinktel Think 365 SBC, Patton SmartNode eSBC, Frafos ABC SBC and Vodia PBX, are listed without media bypass. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Non-media bypass and Media bypass columns. Checked 2026-09-24.
[^14]: Cisco Unified Border Element on ISR 1000, ISR 4000, CSR 1000V and ASR 1000 is listed as supported from IOS XE Amsterdam 17.2.1r and on Catalyst 8000 Edge from 17.3.2, certified for media bypass, with 17.6.1a recommended except 17.3.3 on CSR 1000V. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Cisco rows. Checked 2026-09-24.
[^15]: Direct Routing certification is granted to specific SBC firmware versions, and firmware higher than the documented version is supported as long as the major.minor version is the same. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Introductory Note block, firmware paragraph and Example. Checked 2026-09-24.
[^16]: Oracle AP 1100, AP 3900, AP 3950, AP 4600, AP 4900, AP 6350 and VME are listed as supported on 9.x and 10.x, AP 6300 on 9.x and AP 6400 on 10.x, all certified for media bypass. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Oracle rows. Checked 2026-09-24.
[^17]: Ribbon SBC 5400, SBC 7000 and SBC SWe variants are listed as supported on 11.1 and later, 10.1, 9.2 and 7.2, and Ribbon SBC 1000, SBC 2000 and SBC SWe Edge on 12.x and later, 11.x or 9.x, all certified for media bypass. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Certified SBC vendors table, Ribbon Communications rows. Checked 2026-09-24.
[^18]: Direct Routing supports SILK, G.711, G.722 and G.729 between Teams and the SBC, and AMR-WB only for non-bypass calls. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Supported codecs. Checked 2026-09-24.
[^19]: Tenant dial plans are created with New-CsTenantDialPlan, assigned with Grant-CsTenantDialPlan, tested with Test-CsEffectiveTenantDialPlan -DialedNumber -Identity, and deleted with Remove-CsTenantDialPlan. Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Using PowerShell > Create and manage your dial plans > Using single cmdlets. Checked 2026-09-24.
[^20]: Each tenant dial plan needs at least one normalization rule, and Teams evaluates the rules top down and uses the first rule that matches the dialed number. Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Using the Microsoft Teams admin center > Create a dial plan, steps 3 and 4 with Note. Checked 2026-09-24.
[^21]: Microsoft recommends that all normalization rules produce numbers starting with + to avoid double normalization, and Direct Routing customers can use trunk translation rules to remove the + if the SBC needs it. Source: [Create and manage dial plans](https://learn.microsoft.com/en-us/microsoftteams/create-and-manage-dial-plans), Create a dial plan, Note under step 4. Checked 2026-09-24.
[^22]: Besides registering the SBC domain, the tenant needs a user in that domain with an assigned E3 or E5 license, otherwise pairing fails with an error that the domain was not configured for this tenant. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations, second bullet, follow-on paragraph. Checked 2026-09-24.
[^23]: To assign a user in the SBC domain, the configured authentication type of that domain must be Managed. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations, third bullet. Checked 2026-09-24.
[^24]: The SBC Enabled setting turns the SBC on for outbound calls, defaults to False, and can be used to temporarily remove the SBC from service during updates or maintenance. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, Enabled row. Checked 2026-09-24.
[^25]: FailoverResponseCodes defaults to 408, 503 and 504 and makes Direct Routing try another SBC in the user's voice routing policy on those responses to an initial INVITE, but only when no prior non-100 provisional response was received. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, Failover response codes row. Checked 2026-09-24.
[^26]: If the SBC FQDN uses a subdomain such as sbc.service.contoso.com, the subdomain service.contoso.com must also be registered in the tenant. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use the Microsoft Teams admin center, step 3. Checked 2026-09-24.
[^27]: An SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant, and *.onmicrosoft.com domains are not supported for the SBC FQDN. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use PowerShell > Connect the SBC to the tenant > Considerations, second bullet. Checked 2026-09-24.
[^28]: In the GCC High and DoD clouds the SBC must be connected with PowerShell because the option is not available in the Teams admin center. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Note under the introduction. Checked 2026-09-24.
[^29]: Configuring the global (Org-wide default) online voice routing policy makes every voice-enabled user inherit it, which can route Calling Plan and Operator Connect users' PSTN calls to a Direct Routing trunk, so Microsoft advises custom policies assigned to individual users. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Voice routing policy considerations, Caution item 1. Checked 2026-09-24.
[^30]: The Direct Routing health dashboard, under Voice > Direct Routing in the Teams admin center, shows per-SBC TLS connectivity status with a warning when the certificate expires within 30 days, and a SIP options status of Active, Warning no SIP options, or Warning SIP messages aren't configured. Source: [Health dashboard for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-health-dashboard), View the health dashboard; The SBCs tab, TLS connectivity status and SIP options status. Checked 2026-09-24.
[^31]: A full rollback has to run in reverse build order: unassign users and policies, then remove voice routes that reference the SBC, then remove the SBC, because an SBC still referenced by a voice route cannot be removed (inferred). Source: [Remove-CsOnlinePSTNGateway](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/remove-csonlinepstngateway?view=teams-ps), Description, read with ms-ps-remove-csonlinevoiceroute Description. Checked 2026-09-24.
[^32]: Because the phased bypass trunk is a separately paired SBC FQDN, its domain portion has to meet the same tenant-domain and licensed-user conditions as the first trunk FQDN (inferred). Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations, second bullet, read with ms-learn-dr-media-bypass Configure separate trunks. Checked 2026-09-24.
[^33]: Direct Routing infrastructure requirements include a public IP address reachable by Microsoft Teams and a public DNS entry for the SBC FQDN. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Infrastructure requirements table, Public IP and Public DNS rows. Checked 2026-09-24.
[^34]: Media between Microsoft Media Processors and the SBC is UDP/SRTP on ports 3478 to 3481 and 49152 to 53247 in both directions. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Media ports table. Checked 2026-09-24.
[^35]: A user with Teams Phone but no Calling Plan license whose dialed number matches no voice route in their policy has the call dropped, whereas a Calling Plan user falls back to Calling Plan routing. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1, Note after Call Flow diagrams and paragraph after the third-route diagram. Checked 2026-09-24.
[^36]: Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last three minutes, and an unhealthy SBC is demoted so it is tried after other SBCs in the route rather than first. Source: [Monitor Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-monitor-and-troubleshoot), Monitoring availability of Session Border Controllers using SIP options messages. Checked 2026-09-24.
[^37]: An SBC is paired either in the Teams admin center under Voice > Direct Routing > SBCs > Add, or with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Use the Microsoft Teams admin center; Use PowerShell > Connect the SBC to the tenant. Checked 2026-09-24.
[^38]: A voice routing policy is created with New-CsOnlineVoiceRoutingPolicy <name> -OnlinePstnUsages <usages>, assigned with Grant-CsOnlineVoiceRoutingPolicy -Identity <user> -PolicyName <name>, and checked with Get-CsOnlineUser <user> | select OnlineVoiceRoutingPolicy. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Configuration steps, Using PowerShell, Steps 3 and 4. Checked 2026-09-24.
[^39]: Assigning an online voice routing policy alone does not enable a user to make PSTN calls through Teams; the user must also be enabled for Phone System. Source: [Grant-CsOnlineVoiceRoutingPolicy](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/grant-csonlinevoiceroutingpolicy?view=teams-ps), Description, second paragraph. Checked 2026-09-24.
[^40]: Running Grant-CsOnlineVoiceRoutingPolicy with -PolicyName $null unassigns a user's per-user online voice routing policy, after which the user is governed by the global policy. Source: [Grant-CsOnlineVoiceRoutingPolicy](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/grant-csonlinevoiceroutingpolicy?view=teams-ps), Examples > Example 2. Checked 2026-09-24.
[^41]: A PSTN usage is created with Set-CsOnlinePstnUsage -Identity Global -Usage @{Add="<name>"} or in the admin center under Voice > Direct Routing > Manage PSTN usage records, and listed with (Get-CsOnlinePSTNUsage).Usage. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Configuration steps, Step 1 (admin center and PowerShell). Checked 2026-09-24.
[^42]: Remove-CsOnlinePSTNGateway removes an SBC configuration, and the SBC must be removed from all voice routes before the cmdlet is run. Source: [Remove-CsOnlinePSTNGateway](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/remove-csonlinepstngateway?view=teams-ps), Description. Checked 2026-09-24.
[^43]: Remove-CsOnlineVoiceRoute deletes a voice route without changing any voice routing policy; it only changes routing for numbers that matched the deleted route's pattern. Source: [Remove-CsOnlineVoiceRoute](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/remove-csonlinevoiceroute?view=teams-ps), Description. Checked 2026-09-24.
[^44]: SBCs within one voice route are tried in random order, a lower-priority route matching the same pattern is tried when none of them is available, and the call is dropped if no SBC is available. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Voice routing with one PSTN usage, Call Flow 2 and following paragraph. Checked 2026-09-24.
[^45]: Direct Routing call routing is built from voice routing policies that contain PSTN usages, PSTN usages that contain voice routes, and voice routes that pair a number pattern with a set of online PSTN gateways. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Call routing overview. Checked 2026-09-24.
[^46]: Microsoft supports Teams Phone with Direct Routing only when Microsoft-certified SBCs are used. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Support boundaries. Checked 2026-09-24.
[^47]: Call Analytics does not help with SBC pairing problems or INVITEs rejected for reasons such as a misconfigured trunk FQDN; in those cases the SBC logs carry the detailed description that Direct Routing sends to the SBC. Source: [Monitor Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-monitor-and-troubleshoot), Monitor Call Quality Analytics dashboard and SBC logs, final paragraph. Checked 2026-09-24.
[^48]: The SendSIPOptions setting defaults to True and Microsoft highly recommends leaving it on, because an SBC with it off is excluded from the Monitoring and Alert system. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), SBC settings table, Send SIP options row. Checked 2026-09-24.
[^49]: For Microsoft 365, Office 365 and GCC, the SBC connects to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com in that priority order. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling: FQDNs. Checked 2026-09-24.
[^50]: The commercial Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and the firewall must allow signaling to and from all of these ranges, not only the addresses returned by DNS. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling: FQDNs, IP ranges and Important note. Checked 2026-09-24.
[^51]: SIP/TLS from the SBC to the Microsoft SIP proxy uses destination port 5061, and SIP/TLS from the proxy to the SBC uses the port configured on the SBC. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), SIP signaling ports table. Checked 2026-09-24.
[^52]: For a Direct Routing issue the customer contacts the SBC vendor first, and escalating an SBC-related issue to Microsoft requires an SBC vendor investigation report carrying the vendor ticket reference. Source: [Session Border Controllers certified for Direct Routing - Microsoft Teams](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-border-controllers), Introductory Note block above Certified SBC vendors. Checked 2026-09-24.
[^53]: Direct Routing requires users to be in Teams Only mode, set by assigning the UpgradeToTeams instance of TeamsUpgradePolicy, so incoming calls land in the Teams client. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Assign Teams Only mode to users to ensure calls land in Microsoft Teams. Checked 2026-09-24.
[^54]: The SBC certificate should carry the SBC FQDN as Common Name or Subject Alternative Name, be signed by a CA in the Microsoft Trusted Root Program and include the Server Authentication EKU, and Microsoft recommends generating the CSR on the SBC. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Public trusted certificate for the SBC. Checked 2026-09-24.
[^55]: Wildcard certificates are supported for the SBC when they comply with RFC 2818. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Public trusted certificate for the SBC. Checked 2026-09-24.
[^56]: Microsoft forces TLS 1.2 on the Direct Routing SIP interface, and the SBC must support TLS 1.2 with one of four ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384 or AES128-SHA256. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Considerations, TLS1.2 bullet. Checked 2026-09-24.
[^57]: Remove-CsPhoneNumberAssignment with -NumberType DirectRouting, or -RemoveAll, unassigns the number, leaves it available in the tenant unless an assignment block is set, and automatically sets EnterpriseVoiceEnabled to False. Source: [Remove-CsPhoneNumberAssignment](https://learn.microsoft.com/en-us/powershell/module/microsoftteams/remove-csphonenumberassignment?view=teams-ps), Description and -NumberType parameter. Checked 2026-09-24.
[^58]: PSTN usages in a voice routing policy are applied in order, and once a match is found in one usage the later usages are never evaluated. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 2: Voice routing with multiple PSTN usages, Note under the summary table. Checked 2026-09-24.
[^59]: Direct Routing requires the user to be homed online, which shows as a RegistrarPool value in the infra.lync.com domain in Get-CsOnlineUser output. Source: [Enable users for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-enable-users), Ensure that the user is homed online. Checked 2026-09-24.
[^60]: Direct Routing users require Microsoft Teams and Teams Phone licenses, with additional licensing possibly needed depending on the deployment. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Licensing requirements. Checked 2026-09-24.
[^61]: Microsoft's post-configuration checks are: the SBC reports a healthy connection, inbound and outbound PSTN calls work, emergency calling works if configured, failover between SIP connection points is tested, voice routing policies are correctly assigned, and call quality is validated. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Verify your deployment. Checked 2026-09-24.
[^62]: After pairing, Get-CsOnlinePSTNGateway -Identity <FQDN> should list the SBC with Enabled set to True. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Verify the SBC connection > Check whether the SBC is on the list of paired SBCs. Checked 2026-09-24.
[^63]: Pairing is validated on the SBC management interface by confirming the SBC receives 200 OK to its outgoing OPTIONS and answers 200 OK to OPTIONS arriving from Direct Routing, which Direct Routing sends to the FQDN in the Contact header of the SBC's OPTIONS. Source: [Connect your Session Border Controller (SBC) to Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-connect-the-sbc), Verify the SBC connection > Validate SIP options. Checked 2026-09-24.
[^64]: A voice route is created with New-CsOnlineVoiceRoute using -Identity, -NumberPattern, -OnlinePstnGatewayList, -Priority and -OnlinePstnUsages, or in the admin center under Voice > Direct Routing > Voice routes. Source: [Configure call routing for Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-voice-routing), Example 1: Configuration steps, Step 2 (admin center and PowerShell). Checked 2026-09-24.
[^65]: Direct Routing connects customer telephony infrastructure to Teams Phone through a supported customer-provided Session Border Controller. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Plan Direct Routing, introduction. Checked 2026-09-06.
[^66]: The current Direct Routing plan requires a Microsoft-certified SBC telephony trunks a Microsoft 365 tenant with online users a verified domain a public IP address and DNS record for the SBC FQDN a public certificate and permitted signaling and media paths. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), Infrastructure requirements table. Checked 2026-09-06.
[^67]: Direct Routing isn't supported in Teams Islands coexistence mode. Source: [Plan Direct Routing](https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan), section 'Licensing requirements', Note. Checked 2026-09-23.
