Source record · tier 2 current vendor documentation
What's New Direct Routing
- Publisher
- Microsoft
- URL
- https://learn.microsoft.com/en-us/microsoftteams/direct-routing-whats-new
- Published
- 2026-03-09
- Updated
- unknown
- Accessed
- 2026-09-23
- HTTP status
- 200
- License
- Microsoft Learn terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- Microsoft said that during its 30 June 2026 staged CA validation test, an SBC failing to establish outbound TLS connections or rejecting inbound ones indicated trust problems with the new certificate. in context
- Microsoft's 12 December 2025 Direct Routing update said that at some future point Microsoft would require all SBC certificates to include the Client Authentication EKU. disputed in context
- Microsoft warns that some TLS libraries and SBCs may refuse outbound connections using a client certificate that lacks the Client Authentication EKU, even though the Teams SIP interface accepts such certificates. in context
- Microsoft SIP endpoints currently accept SBC certificates that lack the Client Authentication EKU, and Microsoft expects this to continue for the foreseeable future with advance notice of any change. in context
- Microsoft states that TLS between its SIP endpoints and customer or partner SBCs for Direct Routing and Operator Connect is mutual TLS, with the Microsoft side presenting a client certificate. in context
- Certificates from Microsoft's new CA for the Teams Direct Routing SIP endpoints went into production at the end of July 2026, and the pre-change testing endpoint was discontinued. in context
- Microsoft Teams SIP interface client and server certificates chain to one of seven roots (DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root CA 2017 and Microsoft RSA Root CA 2017), and SBCs must trust all of them. in context
- The discontinued pre-change test endpoint for the new Direct Routing CA was sip.g1.pstnhub.microsoft.com on port 5061, meant only for SIP OPTIONS pings and never for voice traffic. in context
- Microsoft reports that Google's Chrome Root Program Policy v1.6 (February 2025) deprecates the Client Authentication EKU in TLS server certificates, and that from June 2026 certificates must include only the Server Authentication EKU to stay trusted by major browsers. disputed in context
- An SBC that began failing TLS toward Teams Direct Routing around the July 2026 CA rollout, with the failures showing as an unknown_ca or certificate-validation error on the SBC side, most plausibly lacks one of the seven listed roots in the trust store tied to the Teams TLS context. inferred in context
- On non-bypass Direct Routing trunks, Teams outbound offers to the SBC include AMR-WB and telephone-event/16000. On inbound calls, AMR-WB is selected if the SBC's offer includes it. in context
- Microsoft planned a staged validation test for 2026-06-30 at 09:00 UTC that moved Direct Routing SIP endpoints to certificates from a new CA across geos over 2 to 4 days; SBC TLS failures during the test indicated trust issues. in context
- Microsoft's December 2025 update said Microsoft would in future require all SBC certificates to include the Client Authentication EKU. in context
- Microsoft SIP endpoints currently trust Direct Routing SBC certificates that lack the Client Authentication EKU. Microsoft expects this to continue for the foreseeable future and says it will announce any change in advance. in context
- Direct Routing supports IPv6 only for non-media-bypass calls where both SIP and media use IPv6, selected with IPAddressVersion on New-CsOnlinePSTNGateway. Mixed IPv4/IPv6 SIP and media isn't supported. in context
- Microsoft states that Direct Routing SIP endpoint certificates issued by a new CA were rolled out in production at the end of July 2026, and the sip.g1.pstnhub.microsoft.com test endpoint has been discontinued. in context
- Microsoft planned a staged validation test starting June 30 2026 at 09:00 UTC, running over 2-4 days, to move Direct Routing SIP endpoints to certificates from a new CA. It said that SBCs failing outbound TLS or rejecting inbound connections during the test indicated trust issues with the new certificate. in context
- Microsoft says its SIP endpoints currently trust SBC certificates that lack the Client Authentication EKU, expects this to continue for the foreseeable future, and will announce any change in advance. in context
- Whether Microsoft will eventually require the Client Authentication EKU on SBC certificates is unsettled. The December 2025 entry said it would, and the later clarification says the current tolerance should continue for the foreseeable future. Advice that SBC certificates must carry the Client Authentication EKU today is not supported. inferred in context
- Microsoft says certificates issued by a new CA went into production on the Teams Direct Routing SIP endpoints at the end of July 2026. It has discontinued the test endpoint sip.g1.pstnhub.microsoft.com (port 5061, OPTIONS only), which had been provided for validating SBC trust. in context
- Microsoft says Teams SIP interface client and server certificates, for both Direct Routing and Operator Connect, chain to one of seven roots: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root CA 2017, and Microsoft RSA Root CA 2017. SBCs must trust all of them. in context
- SBCs must trust all seven root CAs Microsoft lists for the Teams SIP interface: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root CA 2017 and Microsoft RSA Root CA 2017. in context
Cite this source record
APA
WarmTransfer. (2026, March 9). What's New Direct Routing. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-dr-whats-new
BibTeX
@misc{warmtransfer-ms-learn-dr-whats-new,
title = {What's New Direct Routing},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-dr-whats-new},
note = {Microsoft, accessed 2026-09-23}
}