Setting up outgoing calling permissions in Webex Calling
Webex Calling
Verified 2026-09-30 · 54 sources · tier 2
For Webex Calling administrators configuring outgoing calling policies in Control Hub..
Webex Calling outgoing call permissions control external calling privileges across internal, national, international, and premium destinations 15. This guide walks through setting location-wide call-type rules, digit-pattern overrides, and per-entity exceptions in Control Hub 3147.
Before you start
- Ensure you have administrator access to Control Hub 31.
- If you plan to use the Detailed Call History API to audit call records, ensure your account holds the Webex Calling Detailed Call History API access administrator role and a token with the
spark-admin:calling_cdr_readscope 1716. - See also Setting up a Webex Calling location and Setting up Cloud Connected PSTN for Webex Calling.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Three questions. One permanent page you can send to your manager.
Step 1 Confirm available call types and PSTN restrictions
Do
Navigate to Management > Locations, select the location, and open Calling > Call Handling > Outgoing Call Permissions 31. Review the call types listed: Internal, Toll Free, National, International, Operator Assistance, Chargeable Directory Assistance, Special Services I and II, and Premium Services I and II 15. Note that Cisco Calling Plan is Cisco's bundled PSTN solution 40. During a Cisco Calling Plan trial, International and Premium Services I and II call types are blocked 41, and calls to X11 services other than 911 are unsupported 42.
Verify
Confirm that the Outgoing Call Permissions page is visible and lists the current action for each call type 3115.
Step 2 Record baseline settings
Do
Record the current action, the Allow transfer/forwards status, any active digit patterns, authorization codes, and auto-transfer numbers for the location 3152. For any user or workspace you plan to evaluate, navigate to Management > Users (or Workspaces), select the entity, and open Calling > Call Handling > Outgoing Call Permissions to note whether it uses Location Settings or Custom Settings 4647. To capture an audit baseline, open Management > Security > Audit on the Admin activities tab, filter by category and audit cluster, and export the recent activity to CSV (up to 20,000 events per report) 32.
Verify
Suggested check: verify you have documented every active action, transfer setting, code, and pattern across the location and individual entities.
Step 3 Configure auto-transfer destinations
Block restricted calls outright
Do
No auto-transfer numbers are required when restricted call types are set to Block 1.
Verify
Suggested check: verify that no unnecessary auto-transfer destinations are assigned on the page.
Require an authorization code
Do
No auto-transfer numbers are required when restricted call types require an authorization code 1.
Verify
Suggested check: verify that no unnecessary auto-transfer destinations are assigned on the page.
Auto-transfer calls to an assigned number
Do
WarmTransfer's reading of the sources is that auto-transfer numbers should be configured before a call type or digit pattern is set to Auto-transfer 51. On the location's Auto-transfer numbers page, enter transfer numbers 1, 2, and 3 (up to 3 numbers total) and click Save 5354.
Verify
Confirm that the configured numbers appear in the Auto-transfer numbers list 54.
Rollback
On the Auto-transfer numbers page, click the X next to each number and confirm Delete 54.
Step 4 Configure authorization codes
Block restricted calls outright
Do
No authorization codes are required when restricted call types are set to Block 1.
Verify
Suggested check: verify that no unneeded authorization codes remain active on the location.
Require an authorization code
Do
WarmTransfer's reading of the sources is that authorization codes should be configured before any call type is set to Require Authorization Code 8. Under the location's Authorization Codes page, click Add code, enter a description and the code, and click Add 6. You can configure up to 1,000 codes per location 12. For bulk management, upload a CSV with at most 1,000 codes per file and an Action column set to ADD, REPLACE, or REMOVE 7.
Verify
Confirm that the added codes appear in the Authorization Codes list 6.
Rollback
Select individual codes and click Delete, or click Delete All to clear all location codes 6. Alternatively, upload a CSV with the Action column set to REMOVE 7.
Auto-transfer calls to an assigned number
Do
No authorization codes are required when restricted call types are set to Auto-transfer 1.
Verify
Suggested check: verify that no unneeded authorization codes remain active on the location.
Step 5 Assign permissions by call type
Block restricted calls outright
Do
In the location's Outgoing Call Permissions page under Permissions by call type, set International, Premium Services I and II, and any other restricted types to Block 1. International calls are calls outside the country requiring an international calling code 30, while Premium Services calls provide information or entertainment for a fee charged directly to the caller 43. Set standard business calls such as Internal (calls within the company) and National (calls within the country) to Allow 2932. Click Save 1.
Verify
Confirm that the page displays Block next to each restricted call type and Allow next to permitted types 1.
Rollback
Suggested rollback: change each modified call type back to its baseline setting recorded in Step 2 and save.
Require an authorization code
Do
In the location's Outgoing Call Permissions page under Permissions by call type, set International, Premium Services I and II, and any other restricted types to Require Authorization Code 1. International calls are calls outside the country requiring an international calling code 30, and Premium Services calls charge a caller fee for information or entertainment 43. Set Internal and National calls to Allow 2932. Click Save 1.
Verify
Confirm that the page displays Require Authorization Code next to each restricted call type 1.
Rollback
Suggested rollback: change each modified call type back to its baseline setting recorded in Step 2 and save.
Auto-transfer calls to an assigned number
Do
In the location's Outgoing Call Permissions page under Permissions by call type, set International, Premium Services I and II, and any other restricted types to Auto-transfer to number 1, 2, or 3 1. International calls are calls outside the country requiring an international calling code 30, and Premium Services calls provide information or entertainment charged directly to the caller 43. Set Internal and National calls to Allow 2932. Click Save 1.
Verify
Confirm that the page displays the assigned Auto-transfer slot next to each restricted call type 1.
Rollback
Suggested rollback: change each modified call type back to its baseline setting recorded in Step 2 and save.
Step 6 Configure transfer and forwarding permissions
Do
For each call type, configure the Allow transfer/forwards setting, which determines whether that specific outgoing call type may be transferred or forwarded 52. Note that Chargeable Directory Assistance covers directory assistance companies that charge for calls, and Special Services I and II cover carrier-specific special destination numbers 2744. Save your changes 1.
Verify
Confirm that the transfer/forward toggle displays the expected state for each call type 52.
Rollback
Suggested rollback: restore the toggle states for each call type according to your baseline record.
Step 7 Configure digit patterns
Use call types only
Do
Permissions by digit pattern take precedence over permissions by call type 39. Review the Permissions by digit pattern section under the location's outgoing call permissions to confirm no conflicting digit patterns remain active from previous configurations 39.
Verify
Confirm that no unwanted patterns appear in the Permissions by digit pattern list 35.
Add digit patterns
Do
Under Permissions by digit pattern, click Add digit pattern 35. Enter a unique Name and a unique Pattern (up to 50 characters each), choose a Permission action, optionally select Allow transfers/forwards, and click Add 35. In pattern syntax, X matches 1 digit, ! matches 1 or more digits and must be the last character, [ ] with - defines a digit range, and + may appear only as the first character 38. You can configure up to 500 digit patterns per location, user, workspace, or virtual line 37. For bulk additions, upload a CSV containing at most 500 patterns per file, up to 25 pattern sets per row, with the Action set to ADD, REPLACE, or REMOVE 34. When a dialed number matches multiple patterns, Webex Calling selects the pattern with the fewest expansions, then applies wildcard precedence (exact digit, then range, then X, then !), then lexicographic order 36. Note that permissions by digit pattern take precedence over permissions by call type 39.
Verify
Confirm that each configured pattern appears in the list with its assigned permission 35.
Rollback
On the Permissions by digit pattern page, select an individual pattern and delete it, click Delete all, or upload a CSV file with the Action column set to REMOVE 3534.
Step 8 Apply scope overrides
Apply location default to all entities
Do
Confirm that users and workspaces inherit the location settings by default 47. For any user or workspace, open Management > Users (or Workspaces), select the entity, and navigate to Calling > Call Handling > Outgoing Call Permissions 46. Ensure the setting is toggled to Location Settings 47.
Verify
Confirm that the entity's Outgoing Call Permissions screen shows Location Settings selected 47.
Rollback
Suggested rollback: if an entity previously required a custom profile, reapply Custom Settings and enter its baseline rules.
Apply custom settings to specific users, workspaces, or virtual lines
Do
To override permissions for a user or workspace, go to Management > Users (or Workspaces), select the target entity, and open Calling > Call Handling > Outgoing Call Permissions 46. For virtual lines, navigate to Services > Calling > Virtual Lines 49. Select Custom Settings, customize permissions by type, auto-transfer numbers, digit patterns, or authorization codes, and click Save 4547. Each user, workspace, or virtual line supports up to 1,000 authorization codes and up to 500 digit patterns 1137. Custom digit patterns for an entity are evaluated first, and location settings apply only if none match 26. For virtual lines using Cisco Calling Plan, ensure the Cisco Calling Plan setting is enabled so the line can make outgoing calls 50 (in bulk virtual line CSV uploads, set the Outgoing column to TRUE) 48.
Verify
Confirm that the entity's Outgoing Call Permissions page shows Custom Settings with the specific rules displayed 4547.
Rollback
In the entity's Outgoing Call Permissions page, select Location Settings and save to return it to inheriting the location default 47.
Step 9 Place test calls
Block restricted calls outright
Do
From a test phone or endpoint at the location, dial an outgoing destination belonging to a blocked call type (such as an international number) 30. Then place a control call to an allowed national destination 32.
Verify
Confirm that the call to the blocked destination fails and the control call connects 1. Cisco notes that a call type set to Block under outgoing calling permissions is a common cause of call failures 14.
Require an authorization code
Do
From a test endpoint at the location, dial an outgoing destination belonging to a restricted call type 30. When prompted, enter the authorization code followed by the # key 13.
Verify
Confirm that upon entering the valid code, you hear an announcement that the authorization code is accepted and the call rings 5. Suggested check: place a second call, enter an incorrect code, and verify that the call fails to connect.
Auto-transfer calls to an assigned number
Do
From a test endpoint at the location, dial an outgoing destination belonging to an auto-transfer restricted call type 30.
Verify
Confirm that the call redirects immediately to the configured auto-transfer destination number 153.
Step 10 Audit changes and calling history
Do
To audit administrative updates, navigate to Management > Security > Audit on the Admin activities tab 3. Filter the log and export entries to CSV (up to 20,000 events per report) 2. Note that admin activity events are retained for 3 years in the India audit cluster and 1 year in other clusters, and search covers only the past year 4. In the Webex Calling Detailed Call History report, Pro Pack provides 400 days of history and Standard provides 89 days, with at most 31 days per report run 22. Each call leg generates originating and terminating rows linked by a Correlation ID 2320. Report timestamps are in UTC and cannot be converted to other time zones in the report 24. For automated ingestion, the Detailed Call History API returns calls completed between 48 hours ago and 5 minutes ago 18.
Verify
Confirm that your test calls appear in the report under the Call type field, which reports values including SIP_NATIONAL, SIP_INTERNATIONAL, SIP_TOLLFREE, and SIP_PREMIUM 19. For international test calls, verify that the International country field reflects the dialed country 21.
Applicability
Applies to: Cisco Webex Calling, Cisco Control Hub, Cisco Webex Calling CDR API, and Webex Calling - Cisco Calling Plan. Deployments: multi-tenant. Sources checked 2026-09-30.
What remains uncertain
- The accepted length of authorization codes in Control Hub is not covered by the sources below.
- Whether setting an entity to Custom Settings completely detaches it from future location-level authorization code updates is not covered by the sources below.
- Whether administrative changes to outgoing calling permissions generate entries in the Admin activities log is not covered by the sources below.
- Whether digit patterns evaluate against raw dialed digits or normalized E.164 strings is not covered by the sources below.
- What specific error tone or announcement callers hear when an outgoing call is blocked is not covered by the sources below.
See also
Depends on
- Setting up a Webex Calling location — Permissions are set per location; the location must exist first.
Related to
- Setting up Webex Calling call queues and hunt groups — Sibling Webex Calling configuration guide in the same tranche.
Referenced by
- Setting up Cloud Connected PSTN for Webex Calling — Outbound PSTN reach is governed by calling permissions once the CCP connection is live.
- Setting up a Webex Calling location — Location outgoing permissions are step 9 here; detailed permission design is that guide's subject and needs a location first.
Sources
- 1For each call type an administrator can choose Allow, Block, Require Authorization Code, or Auto-transfer to number 1, 2 or 3.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type' · Checked 2026-09-30
- 2Admin activity log entries can be filtered by category and audit cluster and exported to CSV, with at most 20,000 audit events per report.Review your administrator activity log in Control Hub · filter and export sections · Checked 2026-09-30
- 4Admin activity events are retained for three years in the India audit cluster and one year in other clusters, and search covers only the past year.Review your administrator activity log in Control Hub · retention section · Checked 2026-09-30
- 5After a valid code is entered the caller hears that the authorization code is accepted and the call then rings normally.Configure and Dial International Calling Using Access Code · section on dialing an international call (Verify) · Checked 2026-09-30
- 6To add an authorization code, the administrator opens the Authorization Codes page, clicks Add code, enters a description and the code, and clicks Add; codes are removed with Delete or Delete All.Outgoing call permissions for Webex Calling locations · sections 'Add an authorization code' and 'Delete an authorization code' · Checked 2026-09-30
- 7Authorization codes can be bulk managed by CSV, with at most 1,000 codes per upload and an Action column of ADD, REPLACE or REMOVE.Outgoing call permissions for Webex Calling locations · section 'Bulk manage authorization codes' · Checked 2026-09-30
- 8Authorization codes should exist at the right level before a call type is set to Require Authorization Code, because callers must enter a valid code to place those calls.inferredOutgoing call permissions for Webex Calling locations · sections 'Permissions by call type' and 'Authorization Codes' · Checked 2026-09-30
- 9Authorization codes for Webex Calling international dialing are limited to 2 to 6 numeric digits.disputedConfigure and Dial International Calling Using Access Code · Configure section, Manage Authorization Code step and closing Note · Checked 2026-09-30
- 10A Webex Calling authorization code can be at most 14 digits long.Outgoing call permissions for Webex Calling locations · section 'Authorization Codes' · Checked 2026-09-30
- 11Up to 1,000 authorization codes can be configured for each user, workspace or virtual line.Outgoing call permissions for Webex Calling locations · section 'Authorization Codes' · Checked 2026-09-30
- 12Up to 1,000 authorization codes can be configured per location.Outgoing call permissions for Webex Calling locations · section 'Authorization Codes' · Checked 2026-09-30
- 13When a call type requires an authorization code, the caller is prompted to enter the authorization code followed by the # key.Configure and Dial International Calling Using Access Code · section on dialing an international call (Verify) · Checked 2026-09-30
- 14Cisco's troubleshooting note names a call type set to Block under outgoing calling permissions as a common cause of failed calls.Configure and Dial International Calling Using Access Code · Troubleshoot section · Checked 2026-09-30
- 15Webex Calling outgoing call permissions are set per call type, and the call types are Internal, Toll Free, National, International, Operator Assistance, Chargeable Directory Assistance, Special Services I and II, and Premium Services I and II.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type' · Checked 2026-09-30
- 16The calling user must also hold the Webex Calling Detailed Call History API access administrator role.Understanding the Webex Calling CDR APIs · authorization section · Checked 2026-09-30
- 17Reading detailed call history through the API requires a token with the spark-admin:calling_cdr_read scope.Understanding the Webex Calling CDR APIs · authorization section · Checked 2026-09-30
- 18The Detailed Call History API returns calls completed between 48 hours ago and 5 minutes ago, with times in UTC.Webex Detailed Call History API · section describing query parameters · Checked 2026-09-30
- 19The Webex Calling Detailed Call History report's Call type field includes SIP_NATIONAL, SIP_INTERNATIONAL, SIP_TOLLFREE and SIP_PREMIUM values for outgoing calls.Reports for Your Cloud Collaboration Portfolio · section 'Webex Calling detailed call history report', Call type field · Checked 2026-09-30
- 20The Correlation ID links all rows that belong to the same call.Understand Detailed Call History Report for Webex Calling · background section, Correlation ID · Checked 2026-09-30
- 21The report's International country field gives the country of the dialed number and appears only for international calls.Reports for Your Cloud Collaboration Portfolio · section 'Webex Calling detailed call history report', International country field · Checked 2026-09-30
- 22Pro Pack customers can report on 400 days of detailed call history and Standard customers on 89 days, with at most 31 days per report run.Reports for Your Cloud Collaboration Portfolio · section 'Webex Calling detailed call history report', data availability note · Checked 2026-09-30
- 23The detailed call history report produces separate originating and terminating rows for each call leg, so one call can produce many rows.Understand Detailed Call History Report for Webex Calling · background and example sections · Checked 2026-09-30
- 24Detailed call history report times are in UTC and cannot be converted to other time zones in the report.Understand Detailed Call History Report for Webex Calling · background section, time zone note · Checked 2026-09-30
- 25A user, workspace or virtual line set to Custom Settings probably stops following later changes to the location defaults, because Custom Settings replaces the location default with an administrator-defined set.inferredConfigure call permissions in Control Hub · outgoing call permissions procedure, toggle options · Checked 2026-09-30
- 26Custom digit patterns for a user, workspace or virtual line are applied first, and the location settings apply only if none of them match.Outgoing call permissions for Webex Calling locations · section 'Permissions by digit pattern' · Checked 2026-09-30
- 27Chargeable Directory Assistance calls go to directory assistance companies that charge for the call.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', Chargeable Directory Assistance row · Checked 2026-09-30
- 28When an incoming call is blocked by incoming call permissions, the caller is disconnected without hearing any announcement.Configure call permissions in Control Hub · incoming call permissions section, note · Checked 2026-09-30
- 29Internal calls are calls within the company, including calls to others at the same site and at other locations.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', Internal Calls row · Checked 2026-09-30
- 30International calls are calls to locations outside the caller's country that need an international calling code.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', International Calls row · Checked 2026-09-30
- 32National calls are calls within the caller's country of origin, whether inside or outside the local area code.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', National Calls row · Checked 2026-09-30
- 33If an organization does not have the Cisco calling plan, only internal calls are allowed and all other call types are blocked.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', Internal Calls note · Checked 2026-09-30
- 34Digit patterns can be bulk managed by CSV, with at most 500 patterns per upload, up to 25 pattern sets per row and an Action of ADD, REPLACE or REMOVE.Outgoing call permissions for Webex Calling locations · section 'Bulk manage permissions by digit pattern' · Checked 2026-09-30
- 35Adding a digit pattern requires a unique Name and a unique Pattern (each at most 50 characters) and a Permission, with an optional Allow transfers/forwards check box.Outgoing call permissions for Webex Calling locations · section 'Add digit pattern' · Checked 2026-09-30
- 36When a dialed number matches several digit patterns, Webex Calling picks the pattern with the fewest possible expansions, then applies wildcard precedence (exact digit, then range, then X, then !), then lexicographic order.Outgoing call permissions for Webex Calling locations · section 'Pattern match' · Checked 2026-09-30
- 37Up to 500 digit patterns can be configured per location, user, workspace or virtual line.Outgoing call permissions for Webex Calling locations · section 'Permissions by digit pattern' · Checked 2026-09-30
- 38In a digit pattern, X matches one digit, ! matches one or more digits and must be the last character, [ ] with - defines a digit range, and + may appear only as the first character.Outgoing call permissions for Webex Calling locations · section 'Permissions by digit pattern', wildcard table · Checked 2026-09-30
- 39Permissions by digit pattern take precedence over permissions by call type.Outgoing call permissions for Webex Calling locations · section 'Permissions by digit pattern' · Checked 2026-09-30
- 40The Cisco Calling Plan is Cisco's bundled PSTN solution for Webex Calling.Get Started with the Cisco Calling Plans · overview section · Checked 2026-09-30
- 41During a Cisco Calling Plan trial, International and Premium Services I and II call types are blocked.Get Started with the Cisco Calling Plans · trial restrictions section · Checked 2026-09-30
- 42Apart from 911, Cisco Calling Plans do not support calls to X11 services, including directory service calls.Get Started with the Cisco Calling Plans · limitations section · Checked 2026-09-30
- 44Special Services calls go to carrier-specific number assignments for special services or destinations.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type', Special Services I and II rows · Checked 2026-09-30
- 45To override, the administrator customizes permissions by type, auto-transfer numbers, digit patterns and authorization codes for that user or workspace, chooses Custom settings, and clicks Save.Configure call permissions in Control Hub · outgoing call permissions procedure, steps 5-8 · Checked 2026-09-30
- 47For a user or workspace, Location Settings applies the organization's or location's default outgoing permissions, while Custom Settings lets the administrator define that user's or workspace's own permissions.Configure call permissions in Control Hub · outgoing call permissions procedure, toggle options · Checked 2026-09-30
- 48In the virtual line bulk CSV, the Outgoing column takes TRUE to enable outgoing calls and FALSE to disable them.Multi line support in Webex Calling using virtual lines · bulk add virtual lines CSV column table · Checked 2026-09-30
- 50When creating a virtual line, the administrator turns on the Cisco Calling Plan setting so the line can make outgoing calls.Multi line support in Webex Calling using virtual lines · section on creating a virtual line · Checked 2026-09-30
- 51Auto-transfer numbers should be configured before a call type or digit pattern is set to Auto-transfer, because that action sends calls to the configured number 1, 2 or 3.inferredOutgoing call permissions for Webex Calling locations · sections 'Permissions by call type' and 'Auto-transfer number' · Checked 2026-09-30
- 52The Allow transfer/forwards setting determines whether a specific outgoing call type (or digit pattern) may be transferred or forwarded.Outgoing call permissions for Webex Calling locations · section 'Permissions by call type'; also 'Add digit pattern' step 6 · Checked 2026-09-30
- 53Up to three auto-transfer numbers can be configured as destinations for the Auto-transfer permission action.Outgoing call permissions for Webex Calling locations · section 'Auto-transfer number' · Checked 2026-09-30
- 54Auto-transfer numbers are set on the Auto-transfer numbers page by entering transfer numbers 1, 2 and 3 and clicking Save, and removed by clicking the X next to a number and confirming Delete.Outgoing call permissions for Webex Calling locations · sections 'Add an auto-transfer number' and 'Delete an auto-transfer number' · Checked 2026-09-30
Documents
Configure and Dial International Calling Using Access Code
Configure call permissions in Control Hub
Get Started with the Cisco Calling Plans
Multi line support in Webex Calling using virtual lines
Outgoing call permissions for Webex Calling locations
Reports for Your Cloud Collaboration Portfolio
Review your administrator activity log in Control Hub
Understand Detailed Call History Report for Webex Calling
Understanding the Webex Calling CDR APIs
Webex Detailed Call History API
Cite this page
APA
WarmTransfer. (2026, September 30). Setting up outgoing calling permissions in Webex Calling. WarmTransfer. https://warmtransfer.net/guides/webex-calling-calling-permissions-setup
BibTeX
@misc{warmtransfer-webex-calling-calling-permissions-setup,
title = {Setting up outgoing calling permissions in Webex Calling},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/webex-calling-calling-permissions-setup},
note = {Verified 2026-09-30}
}