Configuration · guide

Setting up Microsoft Teams Direct Routing

Microsoft Teams Phone

Verified 2026-09-24 · 67 sources · tier 2

For Teams voice administrators and partner engineers configuring Session Border Controller pairing and voice routing.

Microsoft Teams Phone Direct Routing connects customer telephony infrastructure to Teams through a supported, customer-provided Session Border Controller (SBC) 65. Microsoft supports Teams Phone with Direct Routing only when Microsoft-certified SBCs are used 46.

Before you start

Direct Routing requires a Microsoft-certified SBC, telephony trunks, a Microsoft 365 tenant with online users, a verified domain, a public IP address and DNS record for the SBC FQDN, a public certificate, and permitted signaling and media network paths 66. Users require Microsoft Teams and Teams Phone licenses and must be homed online 60​59. Direct Routing is not supported in Teams Islands mode 67.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

Which certified Session Border Controller family are you connecting?
How will media flow between Teams clients and the SBC?

Two questions. One permanent page you can send to your manager.

Step 1 Verify certified SBC model and firmware

AudioCodes Mediant SBC

Do

Verify that the Mediant SBC model (AudioCodes Mediant 500, 800, 1000B, 2600, 3100, 4000, 9000, Virtual Edition, or Cloud Edition) is running supported firmware 7.40A.600 or recommended firmware 7.40A.500 12. Firmware higher than the documented version is supported as long as the major.minor version is the same 15. For Direct Routing issues, contact the SBC vendor first 52.

Verify

Confirm that the running firmware on the SBC matches the 7.40A train 15​12.

Rollback

Suggested rollback: No configuration was altered on the SBC during firmware verification.

Ribbon SBC Core or Edge

Do

Verify that the SBC release is 11.1 or later, 10.1, 9.2, or 7.2 for Ribbon SBC 5400, SBC 7000, and SBC SWe, or 12.x or later, 11.x, or 9.x for Ribbon SBC 1000, SBC 2000, and SBC SWe Edge 17. Firmware higher than documented is supported within the same major.minor version 15. For Direct Routing issues, contact the SBC vendor first 52.

Verify

Confirm that the running release matches one of the supported release trains 17.

Rollback

Suggested rollback: No configuration was altered on the SBC during firmware verification.

Oracle Acme Packet

Do

Verify that the platform runs 9.x or 10.x for Oracle AP 1100, AP 3900, AP 3950, AP 4600, AP 4900, AP 6350, and VME; AP 6300 is supported on 9.x and AP 6400 on 10.x 16. Higher firmware is supported within the same major.minor release 15. For Direct Routing issues, contact the SBC vendor first 52.

Verify

Confirm that the running platform firmware matches the listed major.minor train 16​15.

Rollback

Suggested rollback: No configuration was altered on the SBC during firmware verification.

Cisco Unified Border Element

Do

Verify that the Cisco Unified Border Element runs supported IOS XE Amsterdam 17.2.1r or later on ISR 1000, ISR 4000, CSR 1000V, and ASR 1000, or 17.3.2 or later on Catalyst 8000 Edge 14. Cisco recommends release 17.6.1a, or 17.3.3 on CSR 1000V 14. Higher releases are supported within the same major.minor 15. For Direct Routing issues, contact the SBC vendor first 52.

Verify

Confirm that the installed IOS XE version meets or exceeds the required minimum release 14.

Rollback

Suggested rollback: No configuration was altered on the router during firmware verification.

Another certified SBC product

Do

Locate the exact product entry in Microsoft's certified SBC table and verify its supported firmware major.minor train 15. Verify whether the product is certified for media bypass, noting that products such as Thinktel Think 365 SBC, Patton SmartNode eSBC, Frafos ABC SBC, and Vodia PBX are certified without media bypass 13. For Direct Routing issues, contact the SBC vendor first 52.

Verify

Confirm that the running SBC firmware matches the documented certified major.minor release 15.

Rollback

Suggested rollback: No configuration was altered on the SBC during firmware verification.

Step 2 Prepare the SBC domain in the Microsoft 365 tenant

No media bypass: all media flows through Media Processors

Do

Select an SBC FQDN whose domain matches a domain registered in the tenant 27. The default *.onmicrosoft.com domain cannot be used 27. If the SBC FQDN uses a subdomain, register the subdomain in the tenant as well 26. Ensure that the domain's authentication type is set to Managed and that a user in that domain is assigned an E3 or E5 license 22​23.

Verify

Confirm that the domain is verified in the tenant and that a licensed user exists with a UPN in that domain 22.

Rollback

Suggested rollback: Remove the domain only after unpairing the SBC.

Media bypass on a second trunk FQDN for pilot users first

Do

Select a primary SBC FQDN and plan a distinct secondary trunk FQDN on the same SBC 27​9. Register the domain and any subdomains for both FQDNs in the tenant 27​26. The default *.onmicrosoft.com domain cannot be used 27. Ensure that the authentication type for the domain is Managed and that a user in the domain holds an E3 or E5 license 22​23.

Verify

Confirm that both FQDN domains are verified in the tenant and that a licensed user exists in the registered domain 22.

Rollback

Suggested rollback: Remove the domains only after unpairing the SBC trunks.

Media bypass enabled directly on the primary trunk

Do

Select an SBC FQDN whose domain matches a verified tenant domain, excluding *.onmicrosoft.com domains 27. Register any intermediate subdomains in the tenant 26. Set the domain authentication type to Managed and assign an E3 or E5 license to a user in that domain 22​23.

Verify

Confirm that the domain is registered and that an active user in the domain holds an E3 or E5 license 22.

Rollback

Suggested rollback: Remove the domain only after unpairing the SBC.

Step 3 Install the public TLS certificate on the SBC

No media bypass: all media flows through Media Processors

Do

Generate a Certificate Signing Request (CSR) on the SBC 54. Obtain a certificate carrying the SBC FQDN as Common Name (CN) or Subject Alternative Name (SAN), signed by a CA in the Microsoft Trusted Root Program and including the Server Authentication EKU 54. A wildcard certificate adhering to RFC 2818 is supported 55. Install the certificate and root chain on the SBC 54.

Verify

Confirm that the installed certificate includes the SBC FQDN and that the health dashboard shows no certificate expiration warning 30.

Rollback

Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

Media bypass on a second trunk FQDN for pilot users first

Do

Generate a CSR on the SBC 54. Obtain a public certificate covering both trunk FQDNs—either with both names listed in the SAN or via an RFC 2818 wildcard—signed by a Microsoft Trusted Root Program CA and containing the Server Authentication EKU 54​3​55. Install the certificate chain on the SBC 54.

Verify

Confirm that both the primary and phased bypass trunk FQDNs match the SAN entries or wildcard scope 3.

Rollback

Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

Media bypass enabled directly on the primary trunk

Do

Generate a CSR on the SBC and obtain a public certificate issued by a CA in the Microsoft Trusted Root Program with Server Authentication EKU, covering the SBC FQDN in the CN or SAN (or RFC 2818 wildcard) 54​55. Install the certificate on the SBC 54.

Verify

Confirm that the SBC FQDN is covered by the certificate and that the health dashboard indicates valid TLS connectivity 30.

Rollback

Suggested rollback: Reinstall the previous TLS certificate on the SBC interface.

Step 4 Configure DNS records and firewall rules

No media bypass: all media flows through Media Processors

Do

Publish a public DNS record mapping the SBC FQDN to the SBC's public IP address 33. Configure perimeter firewalls to permit outbound SIP/TLS from the SBC to destination port 5061 across 52.112.0.0/14 and 52.120.0.0/14 51​50. Permit inbound SIP/TLS from 52.112.0.0/14 and 52.120.0.0/14 to the SBC's configured signaling port 51​50. Permit bidirectional UDP/SRTP media between the SBC and Microsoft Media Processors on ports 3478 to 3481 and 49152 to 53247 34.

Verify

Confirm that DNS resolves the SBC FQDN to the public IP address and that the SBC receives 200 OK to outgoing OPTIONS 33​63.

Rollback

Suggested rollback: Remove the created firewall access control rules and delete the public DNS record.

Media bypass on a second trunk FQDN for pilot users first

Do

Publish public DNS records for both trunk FQDNs to the SBC public IP 33. Open outbound SIP/TLS to port 5061 and inbound SIP/TLS across 52.112.0.0/14 and 52.120.0.0/14 for both distinct signaling ports 51​50​9. Permit bidirectional Media Processor UDP/SRTP ports 3478 to 3481 and 49152 to 53247 34​6. Permit client-to-SBC UDP/SRTP from client ports 50000 to 50019 to the SBC public IP and media ports 4. Allow Transport Relay traffic across 52.112.0.0/14 with relay source ports 50000 to 59999 and SBC-to-relay destination ports 50000 to 59999 and 3478 to 3481 11.

Verify

Confirm that both signaling ports receive SIP OPTIONS traffic and negotiate 200 OK responses 63.

Rollback

Suggested rollback: Remove the bypass and secondary signaling firewall rules and unpublish the DNS records.

Media bypass enabled directly on the primary trunk

Do

Publish a public DNS record pointing the SBC FQDN to the public IP 33. Open SIP/TLS on destination port 5061 and the SBC signaling port across 52.112.0.0/14 and 52.120.0.0/14 51​50. Permit bidirectional Media Processor UDP/SRTP ports 3478 to 3481 and 49152 to 53247 34​6. Allow client UDP/SRTP from client ports 50000 to 50019 to the SBC media ports, and Transport Relay traffic on 52.112.0.0/14 with relay source ports 50000 to 59999 and destination ports 50000 to 59999 and 3478 to 3481 4​11.

Verify

Confirm that DNS resolves the FQDN and that SIP signaling connects over the configured port 33​63.

Rollback

Suggested rollback: Remove the bypass firewall rules and delete the public DNS record.

Step 5 Configure the SBC SIP trunk interface

Do

Configure the SBC trunk to enforce TLS 1.2 with at least 1 supported ECDHE-RSA cipher suite: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256 56. For Microsoft 365, Office 365, and GCC tenants, point the SIP trunk toward Microsoft connection endpoints in priority order: sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com, and sip3.pstnhub.microsoft.com 49. Configure the SBC to send SIP OPTIONS pings to Microsoft, populating the Contact header with the SBC FQDN 36​63.

Verify

Review the SBC SIP logs to confirm successful TLS establishment and outbound SIP OPTIONS transmission 63. If messages are rejected, inspect SBC logs directly because Call Analytics does not report pairing failures 47.

Rollback

Suggested rollback: Disable or remove the SIP trunk entity and reset TLS profiles on the SBC interface.

Step 6 Pair the SBC with the tenant

Do

Pair the SBC in the Microsoft Teams admin center under Voice > Direct Routing > SBCs > Add, or execute New-CsOnlinePSTNGateway with -Fqdn, -SipSignalingPort, -MaxConcurrentSessions, and -Enabled $true 37. Leave Send SIP options enabled to avoid excluding the SBC from the monitoring system 48.

Verify

If pairing rejects with an error that the domain was not configured for this tenant, verify the licensed user and domain configuration 22.

Rollback

To suspend calling during maintenance, set Enabled to False 24. To remove the gateway, remove it from all voice routes before executing Remove-CsOnlinePSTNGateway 42.

Step 7 Verify gateway status and health metrics

Do

Execute Get-CsOnlinePSTNGateway -Identity and inspect the SBC status in the Teams admin center under Voice > Direct Routing 62​30. Check SBC logs to verify reciprocal 200 OK responses for SIP OPTIONS messages in both directions 63.

Verify

Confirm that Enabled reflects True 62. Confirm that the health dashboard displays SIP options status as Active and shows no TLS connectivity warnings 30.

Rollback

Suggested rollback: No configuration was altered during this verification step.

Step 8 Configure PSTN usages and voice routes

Do

Create a PSTN usage record using Set-CsOnlinePstnUsage -Identity Global -Usage @{Add=""} or in the Teams admin center under Voice > Direct Routing > Manage PSTN usage records 41. Create voice routes using New-CsOnlineVoiceRoute with -Identity, -NumberPattern, -OnlinePstnGatewayList, -Priority, and -OnlinePstnUsages 64. If multiple SBCs are listed in a route, note that Teams attempts them in random order 44.

Verify

Run (Get-CsOnlinePSTNUsage).Usage to verify that the usage appears, and run Get-CsOnlineVoiceRoute to confirm pattern, gateway list, and priority settings 41​64.

Rollback

Delete unnecessary routes using Remove-CsOnlineVoiceRoute, which leaves existing policies intact and only stops matching traffic for that route pattern 43.

Step 9 Configure tenant dial plans

Do

Create dial plans using New-CsTenantDialPlan 19. Define normalization rules that output numbers beginning with a leading +, ordering rules top down 20​21. If the SBC requires dialing without a +, use trunk translation rules rather than stripped dial plan rules 21.

Verify

Test normalization by running Test-CsEffectiveTenantDialPlan -DialedNumber -Identity to ensure translated numbers match intended voice route patterns 19​35.

Rollback

Remove the dial plan using Remove-CsTenantDialPlan -Identity 19.

Step 10 Create online voice routing policies

Do

Create custom voice routing policies using New-CsOnlineVoiceRoutingPolicy -OnlinePstnUsages 38. Sequence PSTN usages so that evaluation stops at the first matching usage 58. Avoid assigning Direct Routing usages directly to the Global policy unless every user in the tenant must inherit them 29.

Verify

Confirm the order of OnlinePstnUsages on the policy, using Set-CsOnlineVoiceRoutingPolicy -OnlinePstnUsages @{Replace=...} to correct the sequence if needed 58.

Rollback

Suggested rollback: Remove the custom voice routing policy after unassigning it from all pilot accounts.

Step 11 Enable pilot user accounts

Do

Verify that pilot users have Microsoft Teams and Teams Phone licenses, are homed online, and are assigned Teams Only mode 60​59​53. Assign the phone number with Set-CsPhoneNumberAssignment -Identity -PhoneNumber -PhoneNumberType DirectRouting, which automatically enables Enterprise Voice 1. Assign the voice routing policy using Grant-CsOnlineVoiceRoutingPolicy -Identity -PolicyName 38.

Verify

Run Get-CsOnlineUser | select OnlineVoiceRoutingPolicy, RegistrarPool to verify that the policy is applied and RegistrarPool resides within infra.lync.com 38​59.

Rollback

Unassign the policy with Grant-CsOnlineVoiceRoutingPolicy -Identity -PolicyName $null to return to Global policy governance 40. Remove the phone number assignment using Remove-CsPhoneNumberAssignment -Identity -PhoneNumber -PhoneNumberType DirectRouting, which sets EnterpriseVoiceEnabled to False 57.

Step 12 Apply media bypass mode

No media bypass: all media flows through Media Processors

Do

Leave media bypass disabled on the paired trunk 8. All media sessions flow through Microsoft Media Processors 34.

Verify

Confirm that Get-CsOnlinePSTNGateway -Identity displays MediaBypass set to False 8.

Rollback

Suggested rollback: No configuration change is required as media bypass remains disabled.

Media bypass on a second trunk FQDN for pilot users first

Do

Configure the secondary trunk on the SBC according to vendor instructions 10. Pair the second FQDN using a different signaling port via New-CsOnlinePSTNGateway 9​37. Enable media bypass on the secondary trunk by executing Set-CsOnlinePSTNGateway -Identity -MediaBypass $true 8. Configure a dedicated voice route and voice routing policy referencing this gateway and assign it to pilot users 9.

Verify

Verify that the secondary trunk displays SIP options as Active in the health dashboard 30. Test pilot calls using desktop, mobile, or Teams Phone devices, noting that web endpoints automatically revert to non-bypass 5.

Rollback

Reassign pilot users to the non-bypass voice routing policy or run Set-CsOnlinePSTNGateway -Identity -MediaBypass $false 38​8.

Media bypass enabled directly on the primary trunk

Do

Configure media bypass parameters on the SBC per vendor guidelines 10. Enable media bypass across the trunk by executing Set-CsOnlinePSTNGateway -Identity -MediaBypass $true 8. Be aware that this immediately alters the media path for all production users on that trunk 2.

Verify

Confirm that MediaBypass reflects True in Get-CsOnlinePSTNGateway output and test calls on supported desktop or mobile clients 8​5.

Rollback

Revert the trunk to non-bypass by executing Set-CsOnlinePSTNGateway -Identity -MediaBypass $false 8.

Step 13 Test calls and failover behavior

Do

Conduct Microsoft's recommended post-configuration validations: inbound and outbound PSTN calling, emergency calling if configured, failover across SIP connection points, voice routing policy assignments, and call quality 61. Dial a number that does not match any route in the assigned policy; for a user without a Calling Plan license, the call must be dropped 35.

Verify

Confirm that calls succeed and that the Direct Routing health dashboard continues to report SIP options status as Active 30. If an SBC ceases sending OPTIONS, confirm that Direct Routing demotes it rather than routing to it first 36.

Rollback

Suggested rollback: If calls fail, review SBC SIP error logs and unassign pilot user policies to halt routing.

See also

Applicability

Applies to: Microsoft Teams Phone, AudioCodes Mediant SBC, Cisco Unified Border Element, Oracle Acme Packet SBC, Ribbon Communications Ribbon SBC Core, MicrosoftTeams PowerShell module, and Microsoft Teams Phone Direct Routing. Deployments: multi-tenant, customer-managed-sbc, dod, and gcc-high. Sources checked 2026-09-24. In GCC High and DoD clouds, SBC pairing must be performed via PowerShell because the Teams admin center does not provide the pairing option 28. Direct Routing supports codecs SILK, G.711, G.722, and G.729, while AMR-WB is supported exclusively on non-bypass calls 18. Media bypass is unsupported when IPv6 is used for SIP or media 7.

What remains uncertain

Whether an administrator can confirm via Microsoft admin tools that a specific call successfully bypassed Media Processors is not covered by the sources below.

Vendor-specific SBC command-line and web interface configuration procedures beyond Microsoft-documented SIP parameters are not covered by the sources below.

See also

Builds on

Configures

Referenced by

  • Microsoft teams phone — Inbound relationship: teams-direct-routing-setup configures microsoft-teams-phone. Direct Routing is one of four PSTN connectivity options for Teams Phone.

Sources

  1. 1
    When the number is managed online, Set-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting assigns the number and automatically enables Enterprise Voice, and the admin center equivalent is Users > Manage users > Account > Assign phone number with type Direct Routing.
    Enable users for Direct Routing · Configure the phone number and enable enterprise voice (admin center and PowerShell) · Checked 2026-09-24
  2. 2
    Turning bypass on for an existing trunk switches all production users at the same time, and initial trunk or port issues may then affect production users, which is why Microsoft recommends the phased approach.
    Configure media bypass with Direct Routing · Migrate from non-bypassed trunks to bypass-enabled trunks, Switch all users at once bullet · Checked 2026-09-24
  3. 3
    When two trunks share one SBC for a phased bypass migration, the certificate must support both trunks, either with both FQDNs in the SAN or with a wildcard certificate.
    Configure media bypass with Direct Routing · Migrate from non-bypassed trunks to bypass-enabled trunks, Phased approach bullet · Checked 2026-09-24
  4. 4
    For direct bypass media the Teams client must reach the SBC's public IP address, with UDP/SRTP between client ports 50000 to 50019 and the media ports defined on the SBC.
    Plan for media bypass with Direct Routing · Media traffic: IP and Port ranges > Requirements for direct media traffic · Checked 2026-09-24
  5. 5
    Media bypass is supported on standalone Teams desktop clients, Android and iOS clients and Teams Phone devices, and calls on other endpoints such as Teams web clients and Skype for Business 3PIP phones are automatically converted to non-bypass.
    Plan for media bypass with Direct Routing · Client endpoints supported with media bypass · Checked 2026-09-24
  6. 6
    Even on a bypass trunk, Media Processors stay in the media path for voice applications such as Call Park, auto attendants and call queues, for web clients, and when a call escalates to a group call, goes to a federated Teams user or is transferred to a Skype for Business user.
    Plan for media bypass with Direct Routing · Use of Media Processors and Transport Relays; Use of Teams Media Processors if trunk is configured for media bypass; Requirements for using media processors · Checked 2026-09-24
  7. 7
    Media bypass is not supported when IPv6 is used for SIP or media or with the IPv6 Teams client, and mixed IPv6/IPv4 SIP and media is not supported.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations, IPAddressVersion bullet · Checked 2026-09-24
  8. 8
    Media bypass is controlled per SBC with Set-CsOnlinePSTNGateway -Identity <FQDN> -MediaBypass set to $true or $false.
    Plan for media bypass with Direct Routing · About media bypass with Direct Routing, second paragraph · Checked 2026-09-24
  9. 9
    Microsoft's recommended phased migration to media bypass creates a second trunk with a different FQDN on the same SBC, using a different TLS signaling port but the same media ports, and a separate online voice routing policy assigned to test users.
    Plan for media bypass with Direct Routing · Configure separate trunks for media bypass and non-media bypass · Checked 2026-09-24
  10. 10
    Turning on media bypass requires that the SBC vendor supports media bypass and provides SBC-side instructions, that bypass is turned on for the trunk, and that the required ports are opened.
    Configure media bypass with Direct Routing · Introduction, numbered conditions 1 to 3 · Checked 2026-09-24
  11. 11
    When bypass media flows through Teams Transport Relays (52.112.0.0/14 in commercial and GCC), relay-to-SBC traffic uses source ports 50000 to 59999 and SBC-to-relay traffic uses destination ports 50000 to 59999 and 3478 to 3481.
    Plan for media bypass with Direct Routing · Media traffic: IP and Port ranges > Requirements for using Transport Relays · Checked 2026-09-24
  12. 12
    AudioCodes Mediant 500, 800, 1000B, 2600, 3100, 4000, 9000, Virtual Edition and Cloud Edition SBCs are listed as certified for both non-bypass and media bypass with supported firmware 7.40A.600 and recommended 7.40A.500.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, AudioCodes rows · Checked 2026-09-24
  13. 13
    The certified SBC table marks non-media-bypass and media-bypass certification separately per product, and some certified products, including Thinktel Think 365 SBC, Patton SmartNode eSBC, Frafos ABC SBC and Vodia PBX, are listed without media bypass.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Non-media bypass and Media bypass columns · Checked 2026-09-24
  14. 14
    Cisco Unified Border Element on ISR 1000, ISR 4000, CSR 1000V and ASR 1000 is listed as supported from IOS XE Amsterdam 17.2.1r and on Catalyst 8000 Edge from 17.3.2, certified for media bypass, with 17.6.1a recommended except 17.3.3 on CSR 1000V.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Cisco rows · Checked 2026-09-24
  15. 15
    Direct Routing certification is granted to specific SBC firmware versions, and firmware higher than the documented version is supported as long as the major.minor version is the same.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Introductory Note block, firmware paragraph and Example · Checked 2026-09-24
  16. 16
    Oracle AP 1100, AP 3900, AP 3950, AP 4600, AP 4900, AP 6350 and VME are listed as supported on 9.x and 10.x, AP 6300 on 9.x and AP 6400 on 10.x, all certified for media bypass.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Oracle rows · Checked 2026-09-24
  17. 17
    Ribbon SBC 5400, SBC 7000 and SBC SWe variants are listed as supported on 11.1 and later, 10.1, 9.2 and 7.2, and Ribbon SBC 1000, SBC 2000 and SBC SWe Edge on 12.x and later, 11.x or 9.x, all certified for media bypass.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Ribbon Communications rows · Checked 2026-09-24
  18. 18
    Direct Routing supports SILK, G.711, G.722 and G.729 between Teams and the SBC, and AMR-WB only for non-bypass calls.
    Plan Direct Routing · Supported codecs · Checked 2026-09-24
  19. 19
    Tenant dial plans are created with New-CsTenantDialPlan, assigned with Grant-CsTenantDialPlan, tested with Test-CsEffectiveTenantDialPlan -DialedNumber -Identity, and deleted with Remove-CsTenantDialPlan.
    Create and manage dial plans · Using PowerShell > Create and manage your dial plans > Using single cmdlets · Checked 2026-09-24
  20. 20
    Each tenant dial plan needs at least one normalization rule, and Teams evaluates the rules top down and uses the first rule that matches the dialed number.
    Create and manage dial plans · Using the Microsoft Teams admin center > Create a dial plan, steps 3 and 4 with Note · Checked 2026-09-24
  21. 21
    Microsoft recommends that all normalization rules produce numbers starting with + to avoid double normalization, and Direct Routing customers can use trunk translation rules to remove the + if the SBC needs it.
    Create and manage dial plans · Create a dial plan, Note under step 4 · Checked 2026-09-24
  22. 22
    Besides registering the SBC domain, the tenant needs a user in that domain with an assigned E3 or E5 license, otherwise pairing fails with an error that the domain was not configured for this tenant.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations, second bullet, follow-on paragraph · Checked 2026-09-24
  23. 23
    To assign a user in the SBC domain, the configured authentication type of that domain must be Managed.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations, third bullet · Checked 2026-09-24
  24. 24
    The SBC Enabled setting turns the SBC on for outbound calls, defaults to False, and can be used to temporarily remove the SBC from service during updates or maintenance.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, Enabled row · Checked 2026-09-24
  25. 25
    FailoverResponseCodes defaults to 408, 503 and 504 and makes Direct Routing try another SBC in the user's voice routing policy on those responses to an initial INVITE, but only when no prior non-100 provisional response was received.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, Failover response codes row · Checked 2026-09-24
  26. 26
    If the SBC FQDN uses a subdomain such as sbc.service.contoso.com, the subdomain service.contoso.com must also be registered in the tenant.
    Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center, step 3 · Checked 2026-09-24
  27. 27
    An SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant, and *.onmicrosoft.com domains are not supported for the SBC FQDN.
    Connect your Session Border Controller (SBC) to Direct Routing · Use PowerShell > Connect the SBC to the tenant > Considerations, second bullet · Checked 2026-09-24
  28. 28
    In the GCC High and DoD clouds the SBC must be connected with PowerShell because the option is not available in the Teams admin center.
    Connect your Session Border Controller (SBC) to Direct Routing · Note under the introduction · Checked 2026-09-24
  29. 29
    Configuring the global (Org-wide default) online voice routing policy makes every voice-enabled user inherit it, which can route Calling Plan and Operator Connect users' PSTN calls to a Direct Routing trunk, so Microsoft advises custom policies assigned to individual users.
    Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 1 · Checked 2026-09-24
  30. 30
    The Direct Routing health dashboard, under Voice > Direct Routing in the Teams admin center, shows per-SBC TLS connectivity status with a warning when the certificate expires within 30 days, and a SIP options status of Active, Warning no SIP options, or Warning SIP messages aren't configured.
    Health dashboard for Direct Routing · View the health dashboard; The SBCs tab, TLS connectivity status and SIP options status · Checked 2026-09-24
  31. 31
    A full rollback has to run in reverse build order: unassign users and policies, then remove voice routes that reference the SBC, then remove the SBC, because an SBC still referenced by a voice route cannot be removed.inferred
    Remove-CsOnlinePSTNGateway · Description, read with ms-ps-remove-csonlinevoiceroute Description · Checked 2026-09-24
  32. 32
    Because the phased bypass trunk is a separately paired SBC FQDN, its domain portion has to meet the same tenant-domain and licensed-user conditions as the first trunk FQDN.inferred
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations, second bullet, read with ms-learn-dr-media-bypass Configure separate trunks · Checked 2026-09-24
  33. 33
    Direct Routing infrastructure requirements include a public IP address reachable by Microsoft Teams and a public DNS entry for the SBC FQDN.
    Plan Direct Routing · Infrastructure requirements table, Public IP and Public DNS rows · Checked 2026-09-24
  34. 34
    Media between Microsoft Media Processors and the SBC is UDP/SRTP on ports 3478 to 3481 and 49152 to 53247 in both directions.
    Plan Direct Routing · Media ports table · Checked 2026-09-24
  35. 35
    A user with Teams Phone but no Calling Plan license whose dialed number matches no voice route in their policy has the call dropped, whereas a Calling Plan user falls back to Calling Plan routing.
    Configure call routing for Direct Routing · Example 1, Note after Call Flow diagrams and paragraph after the third-route diagram · Checked 2026-09-24
  36. 36
    Direct Routing treats an SBC as healthy if it sent SIP OPTIONS within the last three minutes, and an unhealthy SBC is demoted so it is tried after other SBCs in the route rather than first.
    Monitor Direct Routing · Monitoring availability of Session Border Controllers using SIP options messages · Checked 2026-09-24
  37. 37
    An SBC is paired either in the Teams admin center under Voice > Direct Routing > SBCs > Add, or with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true.
    Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center; Use PowerShell > Connect the SBC to the tenant · Checked 2026-09-24
  38. 38
    A voice routing policy is created with New-CsOnlineVoiceRoutingPolicy <name> -OnlinePstnUsages <usages>, assigned with Grant-CsOnlineVoiceRoutingPolicy -Identity <user> -PolicyName <name>, and checked with Get-CsOnlineUser <user> | select OnlineVoiceRoutingPolicy.
    Configure call routing for Direct Routing · Example 1: Configuration steps, Using PowerShell, Steps 3 and 4 · Checked 2026-09-24
  39. 39
    Assigning an online voice routing policy alone does not enable a user to make PSTN calls through Teams; the user must also be enabled for Phone System.
    Grant-CsOnlineVoiceRoutingPolicy · Description, second paragraph · Checked 2026-09-24
  40. 40
    Running Grant-CsOnlineVoiceRoutingPolicy with -PolicyName $null unassigns a user's per-user online voice routing policy, after which the user is governed by the global policy.
    Grant-CsOnlineVoiceRoutingPolicy · Examples > Example 2 · Checked 2026-09-24
  41. 41
    A PSTN usage is created with Set-CsOnlinePstnUsage -Identity Global -Usage @{Add="<name>"} or in the admin center under Voice > Direct Routing > Manage PSTN usage records, and listed with (Get-CsOnlinePSTNUsage).Usage.
    Configure call routing for Direct Routing · Example 1: Configuration steps, Step 1 (admin center and PowerShell) · Checked 2026-09-24
  42. 42
    Remove-CsOnlinePSTNGateway removes an SBC configuration, and the SBC must be removed from all voice routes before the cmdlet is run.
    Remove-CsOnlinePSTNGateway · Description · Checked 2026-09-24
  43. 43
    Remove-CsOnlineVoiceRoute deletes a voice route without changing any voice routing policy; it only changes routing for numbers that matched the deleted route's pattern.
    Remove-CsOnlineVoiceRoute · Description · Checked 2026-09-24
  44. 44
    SBCs within one voice route are tried in random order, a lower-priority route matching the same pattern is tried when none of them is available, and the call is dropped if no SBC is available.
    Configure call routing for Direct Routing · Example 1: Voice routing with one PSTN usage, Call Flow 2 and following paragraph · Checked 2026-09-24
  45. 45
    Direct Routing call routing is built from voice routing policies that contain PSTN usages, PSTN usages that contain voice routes, and voice routes that pair a number pattern with a set of online PSTN gateways.
    Configure call routing for Direct Routing · Call routing overview · Checked 2026-09-24
  46. 46
    Microsoft supports Teams Phone with Direct Routing only when Microsoft-certified SBCs are used.
    Plan Direct Routing · Support boundaries · Checked 2026-09-24
  47. 47
    Call Analytics does not help with SBC pairing problems or INVITEs rejected for reasons such as a misconfigured trunk FQDN; in those cases the SBC logs carry the detailed description that Direct Routing sends to the SBC.
    Monitor Direct Routing · Monitor Call Quality Analytics dashboard and SBC logs, final paragraph · Checked 2026-09-24
  48. 48
    The SendSIPOptions setting defaults to True and Microsoft highly recommends leaving it on, because an SBC with it off is excluded from the Monitoring and Alert system.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table, Send SIP options row · Checked 2026-09-24
  49. 49
    For Microsoft 365, Office 365 and GCC, the SBC connects to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com in that priority order.
    Plan Direct Routing · SIP signaling: FQDNs · Checked 2026-09-24
  50. 50
    The commercial Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and the firewall must allow signaling to and from all of these ranges, not only the addresses returned by DNS.
    Plan Direct Routing · SIP signaling: FQDNs, IP ranges and Important note · Checked 2026-09-24
  51. 51
    SIP/TLS from the SBC to the Microsoft SIP proxy uses destination port 5061, and SIP/TLS from the proxy to the SBC uses the port configured on the SBC.
    Plan Direct Routing · SIP signaling ports table · Checked 2026-09-24
  52. 52
    For a Direct Routing issue the customer contacts the SBC vendor first, and escalating an SBC-related issue to Microsoft requires an SBC vendor investigation report carrying the vendor ticket reference.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Introductory Note block above Certified SBC vendors · Checked 2026-09-24
  53. 53
    Direct Routing requires users to be in Teams Only mode, set by assigning the UpgradeToTeams instance of TeamsUpgradePolicy, so incoming calls land in the Teams client.
    Enable users for Direct Routing · Assign Teams Only mode to users to ensure calls land in Microsoft Teams · Checked 2026-09-24
  54. 54
    The SBC certificate should carry the SBC FQDN as Common Name or Subject Alternative Name, be signed by a CA in the Microsoft Trusted Root Program and include the Server Authentication EKU, and Microsoft recommends generating the CSR on the SBC.
    Plan Direct Routing · Public trusted certificate for the SBC · Checked 2026-09-24
  55. 55
    Wildcard certificates are supported for the SBC when they comply with RFC 2818.
    Plan Direct Routing · Public trusted certificate for the SBC · Checked 2026-09-24
  56. 56
    Microsoft forces TLS 1.2 on the Direct Routing SIP interface, and the SBC must support TLS 1.2 with one of four ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384 or AES128-SHA256.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations, TLS1.2 bullet · Checked 2026-09-24
  57. 57
    Remove-CsPhoneNumberAssignment with -NumberType DirectRouting, or -RemoveAll, unassigns the number, leaves it available in the tenant unless an assignment block is set, and automatically sets EnterpriseVoiceEnabled to False.
    Remove-CsPhoneNumberAssignment · Description and -NumberType parameter · Checked 2026-09-24
  58. 58
    PSTN usages in a voice routing policy are applied in order, and once a match is found in one usage the later usages are never evaluated.
    Configure call routing for Direct Routing · Example 2: Voice routing with multiple PSTN usages, Note under the summary table · Checked 2026-09-24
  59. 59
    Direct Routing requires the user to be homed online, which shows as a RegistrarPool value in the infra.lync.com domain in Get-CsOnlineUser output.
    Enable users for Direct Routing · Ensure that the user is homed online · Checked 2026-09-24
  60. 60
    Direct Routing users require Microsoft Teams and Teams Phone licenses, with additional licensing possibly needed depending on the deployment.
    Plan Direct Routing · Licensing requirements · Checked 2026-09-24
  61. 61
    Microsoft's post-configuration checks are: the SBC reports a healthy connection, inbound and outbound PSTN calls work, emergency calling works if configured, failover between SIP connection points is tested, voice routing policies are correctly assigned, and call quality is validated.
    Plan Direct Routing · Verify your deployment · Checked 2026-09-24
  62. 62
    After pairing, Get-CsOnlinePSTNGateway -Identity <FQDN> should list the SBC with Enabled set to True.
    Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection > Check whether the SBC is on the list of paired SBCs · Checked 2026-09-24
  63. 63
    Pairing is validated on the SBC management interface by confirming the SBC receives 200 OK to its outgoing OPTIONS and answers 200 OK to OPTIONS arriving from Direct Routing, which Direct Routing sends to the FQDN in the Contact header of the SBC's OPTIONS.
    Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection > Validate SIP options · Checked 2026-09-24
  64. 64
    A voice route is created with New-CsOnlineVoiceRoute using -Identity, -NumberPattern, -OnlinePstnGatewayList, -Priority and -OnlinePstnUsages, or in the admin center under Voice > Direct Routing > Voice routes.
    Configure call routing for Direct Routing · Example 1: Configuration steps, Step 2 (admin center and PowerShell) · Checked 2026-09-24
  65. 65
    Direct Routing connects customer telephony infrastructure to Teams Phone through a supported customer-provided Session Border Controller.
    Plan Direct Routing · Plan Direct Routing, introduction · Checked 2026-09-06
  66. 66
    The current Direct Routing plan requires a Microsoft-certified SBC telephony trunks a Microsoft 365 tenant with online users a verified domain a public IP address and DNS record for the SBC FQDN a public certificate and permitted signaling and media paths.
    Plan Direct Routing · Infrastructure requirements table · Checked 2026-09-06
  67. 67
    Direct Routing isn't supported in Teams Islands coexistence mode.
    Plan Direct Routing · section 'Licensing requirements', Note · Checked 2026-09-23

Documents

tier 2 current vendor documentation

Configure call routing for Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

Configure media bypass with Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-24

tier 2 current vendor documentation

Connect your Session Border Controller (SBC) to Direct Routing

Microsoft · 2026-04-26 · accessed 2026-09-21

tier 2 current vendor documentation

Create and manage dial plans

Microsoft · 2025-04-25 · accessed 2026-09-21

tier 2 current vendor documentation

Enable users for Direct Routing

Microsoft · 2026-08-21 · accessed 2026-09-21

tier 2 current vendor documentation

Grant-CsOnlineVoiceRoutingPolicy

Microsoft · 2026-05-06 · accessed 2026-09-24

tier 2 current vendor documentation

Health dashboard for Direct Routing

Microsoft · 2026-04-29 · accessed 2026-09-24

tier 2 current vendor documentation

Monitor Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

Plan Direct Routing

Microsoft (Microsoft Learn) · 2026-08-21 · accessed 2026-09-06

tier 2 current vendor documentation

Plan for media bypass with Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-16

tier 2 current vendor documentation

Remove-CsOnlinePSTNGateway

Microsoft · 2026-04-27 · accessed 2026-09-24

tier 2 current vendor documentation

Remove-CsOnlineVoiceRoute

Microsoft · 2026-04-27 · accessed 2026-09-24

tier 2 current vendor documentation

Remove-CsPhoneNumberAssignment

Microsoft · 2026-08-07 · accessed 2026-09-24

tier 2 current vendor documentation

Session Border Controllers certified for Direct Routing - Microsoft Teams

Microsoft · 2026-05-27 · accessed 2026-09-14

Cite this page

APA

WarmTransfer. (2026, September 24). Setting up Microsoft Teams Direct Routing. WarmTransfer. https://warmtransfer.net/guides/teams-direct-routing-setup

BibTeX

@misc{warmtransfer-teams-direct-routing-setup,
  title  = {Setting up Microsoft Teams Direct Routing},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/teams-direct-routing-setup},
  note   = {Verified 2026-09-24}
}