Source record · tier 2 current vendor documentation
Securing Teams media traffic for VPN split tunneling
- Publisher
- Microsoft
- URL
- https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-vpn-securing-teams
- Published
- 2024-10-03
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Microsoft Learn terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- For Teams media to follow the intended route in all VPN scenarios, Microsoft requires Teams client version 1.3.00.13565 or later. in context
- The Microsoft article says Microsoft Edge 96 and later supports VPN split tunnelling for peer-to-peer traffic, and that the Teams web client on Edge needs an extra step involving the Edge WebRtcRespectOsRoutingTableEnabled policy (the article says to disable it). in context
- Microsoft says Teams media can still traverse the VPN tunnel even with the correct routes in place, and that a firewall rule blocking the Teams IP subnets or ports from using the VPN should then suffice. in context
- Teams media traffic has no URL, so VPN split-tunnel routing for Teams media must be controlled by IP subnets rather than URL- or FQDN-based rules. in context
- Microsoft's security argument for split tunnelling Teams media is that the media is already encrypted with SRTP, using a session key exchanged over the TLS-secured signalling channel. in context
- Teams signalling runs over HTTPS, is categorised Allow rather than Optimize, and Microsoft says it can safely be routed through the VPN. in context
- Microsoft suggests three ways to confirm Teams media is using the local internet path: the Microsoft 365 connectivity test, a tracert to worldaz.tr.teams.microsoft.com that shows the local ISP path, and a packet capture showing UDP to an IP in the Teams Optimize range during a call. in context
Cite this source record
APA
WarmTransfer. (2024, October 3). Securing Teams media traffic for VPN split tunneling. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-m365-vpn-securing-teams
BibTeX
@misc{warmtransfer-ms-learn-m365-vpn-securing-teams,
title = {Securing Teams media traffic for VPN split tunneling},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-m365-vpn-securing-teams},
note = {Microsoft, accessed 2026-09-25}
}