Source record · tier 2 current vendor documentation
Plan for media bypass with Direct Routing
- Publisher
- Microsoft
- URL
- https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan-media-bypass
- Published
- 2026-09-10
- Updated
- unknown
- Accessed
- 2026-09-16
- HTTP status
- 200
- License
- not stated on page; Microsoft Learn Terms of Use apply; no-redistribution; short excerpts and locators only
Source notes citing this source
- To trial media bypass, Microsoft describes two trunks with different FQDNs pointing to the same SBC (different TLS signaling ports, same media ports, a certificate covering both names) and a separate voice routing policy for test users. in context
- Media bypass is controlled per SBC with Set-CsOnlinePSTNGateway -MediaBypass; with bypass, media can flow directly between the Teams client and the SBC, but SIP signaling always flows through the Microsoft cloud. in context
- Teams Media Processors are always in the media path for voice applications such as Call Park, auto attendants and call queues, even when the trunk uses media bypass. in context
- Media bypass keeps media between the SBC and the client instead of sending it via Microsoft Teams Phone, and to configure it the SBC and the client must be in the same location or network. in context
- For direct media between a Teams client and the SBC, UDP/SRTP is required on destination ports 50000-50019 at the SBC, whereas media to and from Microsoft Media Processors uses 3478-3481 and 49152-53247. in context
- Media bypass is supported with standalone Teams desktop clients, Android and iOS clients and Teams Phone devices; for other endpoints that don't support media bypass, including Skype for Business 3PIP phones and WebRTC-based web clients, the call is converted to non-bypass automatically. in context
- Media bypass uses ICE on the Teams client and ICE Lite on the SBC, and Microsoft points readers to RFC 5245 for those protocols. in context
- Teams Transport Relays have two versions - v4 requiring port range 50000 to 59999 and v6 working with 3478 to 3481 - and Microsoft recommends at least two ports per concurrent call on the SBC. in context
- To move from non-media bypass to media bypass while confirming functionality first, Microsoft documents creating a second trunk with a different FQDN pointing at the same SBC, with different TLS SIP signalling ports, a separate Online Voice Routing policy, and that policy assigned only to identified pilot users. in context
- Media bypass is controlled per SBC with the Set-CSOnlinePSTNGateway command and the -MediaBypass parameter set to true or false, and enabling it does not mean all media traffic stays within the corporate network. in context
- Media Processors are always in the media path for non-bypassed end-user calls and always in the media path for voice applications such as Call Park, Organizational Auto Attendant and Call Queues, and never in the path for bypassed end-user calls. in context
- Media Processors are a B2BUA and can transcode (for example SILK from the Teams client to G.711 toward the SBC), while Transport Relays are not a B2BUA and never change the codec between the client and the SBC even when traffic flows via relays. in context
- In a bypassed Direct Routing call the Media Processor is never in the path, so the client and SBC must share a codec directly because no Microsoft component transcodes. inferred in context
- The Teams Media Processor is a B2BUA that can transcode (for example SILK toward the client and G.711 toward the SBC), whereas Transport Relays never change the codec between client and SBC. in context
- Media Processors are always in the media path for Teams voice applications such as Call Park, Auto Attendant and Call Queues, and for web clients, even on media-bypass trunks. in context
- Media bypass is controlled per SBC with the -MediaBypass parameter of Set-CsOnlinePSTNGateway. It uses ICE on the Teams client and ICE Lite on the SBC, and signaling always flows through the Microsoft cloud. in context
- With media bypass, Teams clients send media to the SBC's public IP from UDP source ports 50000–50019. Transport Relays use 50000–59999 (v4 relays) and 3478–3481 (v6 relays) toward the SBC. in context
- GCC High uses the single Direct Routing FQDN sip.pstnhub.gov.teams.microsoft.us (52.127.88.0/21), and DoD uses sip.pstnhub.dod.teams.microsoft.us (52.127.64.0/21). Neither has secondary or tertiary FQDNs. in context
- The media bypass planning article lists only 52.112.0.0/14 as the Media Processor and Transport Relay IPv4 range for Office 365 and GCC. disputed in context
- Even on media-bypass trunks, Teams Media Processors are always in the media path for voice applications such as Call Park, Auto Attendant and Call Queues, and for web clients. in context
- For direct bypass media the Teams client must reach the SBC's public IP address, with UDP/SRTP between client ports 50000 to 50019 and the media ports defined on the SBC. in context
- Media bypass is supported on standalone Teams desktop clients, Android and iOS clients and Teams Phone devices, and calls on other endpoints such as Teams web clients and Skype for Business 3PIP phones are automatically converted to non-bypass. in context
- Even on a bypass trunk, Media Processors stay in the media path for voice applications such as Call Park, auto attendants and call queues, for web clients, and when a call escalates to a group call, goes to a federated Teams user or is transferred to a Skype for Business user. in context
- Media bypass is controlled per SBC with Set-CsOnlinePSTNGateway -Identity <FQDN> -MediaBypass set to $true or $false. in context
- Microsoft's recommended phased migration to media bypass creates a second trunk with a different FQDN on the same SBC, using a different TLS signaling port but the same media ports, and a separate online voice routing policy assigned to test users. in context
- When bypass media flows through Teams Transport Relays (52.112.0.0/14 in commercial and GCC), relay-to-SBC traffic uses source ports 50000 to 59999 and SBC-to-relay traffic uses destination ports 50000 to 59999 and 3478 to 3481. in context
- SIP/TLS from the SBC to the Microsoft SIP proxy uses destination port 5061. Traffic from the proxy to the SBC uses the port configured on the SBC, from source ports 1024 to 65535. in context
Cite this source record
APA
WarmTransfer. (2026, September 10). Plan for media bypass with Direct Routing. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-dr-media-bypass
BibTeX
@misc{warmtransfer-ms-learn-dr-media-bypass,
title = {Plan for media bypass with Direct Routing},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-dr-media-bypass},
note = {Microsoft, accessed 2026-09-16}
}