Source record · tier 2 current vendor documentation
Configure SIP Gateway
- Publisher
- Microsoft
- URL
- https://learn.microsoft.com/en-us/microsoftteams/devices/sip-gateway-configure
- Published
- 2024-08-08
- Updated
- unknown
- Accessed
- 2026-09-21
- HTTP status
- 200
- License
- Microsoft Learn terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- Bulk sign-in of SIP devices works in batches of up to 100 devices with at most three concurrent batches per region, requires the site public IP to have been a trusted IP for at least 24 hours, the tenant ID in the provisioning URL, Teams PowerShell 5.6.0 or later, accounts without MFA that hold a phone number, the CommonAreaPhone policy and AllowSIPDevicesCalling. in context
- SIP Gateway is enabled for users through a Teams calling policy, either with the 'SIP devices can be used for calls' setting in Teams admin center or Set-CsTeamsCallingPolicy -AllowSIPDevicesCalling True, the default being False, and policy propagation may take up to 24 hours. in context
- Every SIP device must be reset to factory default settings before it is used with SIP Gateway, and only compatible SIP devices can be onboarded. in context
- SIP Gateway requires outbound-only firewall openings of UDP ports 49152 to 53247 and TCP port 5061 towards IP ranges 52.112.0.0/14 and 52.122.0.0/15, the devices must not sit behind an HTTP proxy, and SIP Gateway supports IPv4 only. in context
- SIP Gateway provisioning server URLs are regional - emea.ipp.sdg.teams.microsoft.com, noam.ipp.sdg.teams.microsoft.com and apac.ipp.sdg.teams.microsoft.com - and for Cisco devices the URL must have /$PSN.xml appended and is delivered with DHCP option 160. in context
- SIP Gateway falls back to emergency calling based on registered addresses for devices that do not share location attributes, and registered addresses are not currently supported for Direct Routing scenarios. in context
- SIP Gateway bulk sign-in signs in shared accounts in batches of up to 100 devices, with at most 3 concurrent batches per region. It works only within 72 hours of onboarding, or within 7 days of a device being signed out. Accounts must have CommonAreaPhone policy, a phone number and AllowSIPDevicesCalling, and must not have MFA. in context
- From January 1, 2026, tenants that use location-based Conditional Access exclusions for SIP Gateway must also exclude additional SIP Gateway service IPs in the 70.152.x.x range, for each region. in context
- To let users make calls from SIP devices, admins set AllowSIPDevicesCalling to True in the Teams calling policy (the default is False), or turn on SIP devices can be used for calls in the Teams admin center. Propagation can take up to 24 hours. in context
- To enroll a SIP device as a common area phone, in this order: onboard it to SIP Gateway; add its MAC address under Teams devices > SIP devices > Provision devices; generate a verification code; dial *55* followed by the code on the device; then sign in with the pairing code shown in the Sign in a user dialog. in context
- SIP Gateway supports only IPv4, although the Teams service and clients support both IPv4 and IPv6. in context
- SIP Gateway provisioning server URLs are http://emea.ipp.sdg.teams.microsoft.com, http://noam.ipp.sdg.teams.microsoft.com and http://apac.ipp.sdg.teams.microsoft.com. They are set through DHCP option 66 for Yealink and Alcatel-Lucent Enterprise, or option 160 for Cisco, Poly and AudioCodes. Cisco devices also need /$PSN.xml appended. in context
Cite this source record
APA
WarmTransfer. (2024, August 8). Configure SIP Gateway. WarmTransfer. https://warmtransfer.net/knowledge/sources/ms-learn-sip-gateway-configure
BibTeX
@misc{warmtransfer-ms-learn-sip-gateway-configure,
title = {Configure SIP Gateway},
author = {{WarmTransfer}},
year = {2024},
url = {https://warmtransfer.net/knowledge/sources/ms-learn-sip-gateway-configure},
note = {Microsoft, accessed 2026-09-21}
}