Source record · tier 2 current vendor documentation
Direct Routing support for media bypass - Microsoft Teams
- Publisher
- Microsoft Learn
- URL
- https://learn.microsoft.com/en-us/microsoftteams/direct-routing-protocols-media
- Published
- 2026-09-10
- Updated
- unknown
- Accessed
- 2026-09-23
- HTTP status
- 200
- License
- Microsoft Learn terms of use (CC BY 4.0 for docs content; code under MIT); no-redistribution; short excerpts and locators only
Source notes citing this source
- For media bypass early media, Microsoft says the SBC should support sending DTMF during the early-media phase to enable IVR and voicemail scenarios. in context
- With media bypass, non-audio m= lines such as m=video are not stripped by the service, and the SBC must answer each with a corresponding m= line with port zero per RFC 3264. in context
- In media bypass mode an SBC offer must contain SDES and may optionally also contain DTLS parameters. in context
- Microsoft states that MKI and length parameters are not required in the Direct Routing crypto attribute. in context
- Microsoft's example SDES-only offer from Teams to the SBC carries two crypto lines, AES_CM_128_HMAC_SHA1_32 and AES_CM_128_HMAC_SHA1_80, on an RTP/SAVP m= line. in context
- Microsoft Media Processors always prefer SDES, convert DTLS-only clients to SDES in non-bypass calls, and always use SDES on the SBC-to-Media-Processor leg. in context
- For Direct Routing the SBC must support SRTP cipher AES_CM_128_HMAC_SHA1_80 in both offer and answer using the inline key||salt format with optional lifetime. in context
- AES_CM_128_HMAC_SHA1_80 keyed by SDES is the one SRTP configuration that both Teams Direct Routing and Webex Calling document as required or supported, so an SBC serving both needs it in its crypto list. inferred in context
- With Direct Routing media bypass, if the Teams client is DTLS-only, Direct Routing inserts a media processor and converts the call to non-bypass. Microsoft says no current Teams client offers only DTLS. in context
- In Direct Routing bypass mode, the SBC's offer must contain SDES (a=crypto) and may also carry DTLS attributes (a=fingerprint, a=setup:actpass). Microsoft's example uses UDP/TLS/RTP/SAVP with rtcp-mux. in context
- Microsoft Media Processors always prefer SDES, and SDES is always used between the SBC and the Direct Routing media processor. Without media bypass, a DTLS-only client is converted to SDES by the media processor. in context
- Microsoft requires a Direct Routing SBC to support the SRTP cipher AES_CM_128_HMAC_SHA1_80 in offers and answers, using the inline:<key||salt>[|lifetime] format. MKI and length parameters are not required. in context
- Microsoft's example of an SDES-only offer from Teams to an SBC lists AES_CM_128_HMAC_SHA1_32 as crypto tag 0 ahead of AES_CM_128_HMAC_SHA1_80 as tag 1, on an RTP/SAVP media line. in context
Cite this source record
APA
WarmTransfer. (2026, September 10). Direct Routing support for media bypass - Microsoft Teams. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-dr-protocols-media
BibTeX
@misc{warmtransfer-ms-learn-dr-protocols-media,
title = {Direct Routing support for media bypass - Microsoft Teams},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-dr-protocols-media},
note = {Microsoft Learn, accessed 2026-09-23}
}