Microsoft Teams Direct Routing: what the SBC has to do
Direct Routing connects Microsoft Teams to your own carrier through a session border controller you operate. Microsoft is strict about how that SBC identifies itself. Most failed first connections come down to one of the items below.
A name Microsoft can verify
- The SBC needs a public name, such as
sbc1.example.com, with a public DNS record. - The domain part must be a verified domain in your Microsoft 365 tenant. The default
onmicrosoft.comdomain is not accepted. - A new subdomain must be added to the tenant before the SBC is paired.
A certificate that matches the name
- The certificate must come from a public certificate authority that Microsoft trusts.
- The SBC name must be the certificate's common name or one of its alternative names. A wildcard certificate is accepted when it covers the SBC name directly:
*.example.comcoverssbc1.example.comand does not coversbc1.eu.example.com. - The SBC must also trust the certificate authorities Microsoft uses, because both sides present a certificate.
Signaling
- SIP over TLS to port 5061.
- Three Microsoft entry points, used in this order:
sip.pstnhub.microsoft.com,sip2.pstnhub.microsoft.com,sip3.pstnhub.microsoft.com. The GCC High and DoD government clouds use different names. - Allow traffic to and from the whole published Microsoft address range, not only the addresses the names resolve to today.
- The SBC must put its own public name in the messages it sends. Teams matches that name against the tenant. An address in its place is rejected.
- Teams checks each SBC with regular SIP OPTIONS messages and expects the SBC to send its own.
Media
- Media is encrypted with SRTP.
- Allow Microsoft's published media port ranges in both directions. On the SBC, size your own media port range for at least two ports per concurrent call.
- Supported codecs include SILK, G.711, G.722 and G.729. Offer G.711 at a minimum.
- Decide whether media goes through Microsoft or directly between the Teams client and the SBC. The direct option changes the firewall rules and where the SBC must be reachable from.
Routing inside Teams
An SBC that shows as healthy still carries no calls until Teams is told to use it. That takes a voice route with a number pattern pointing at the SBC, a usage that groups routes, and a voice routing policy assigned to each user. Each user also needs a Microsoft Teams license with Teams Phone, and a phone number.
Check before the first call
- The public name resolves to the SBC's public address.
- The certificate is valid for that name, with its full chain installed.
- The SBC's OPTIONS messages are answered with 200 OK.
- The Teams admin center shows the SBC as active.
- A test user has a license, a number and a routing policy.
Address ranges and port ranges change. Read them from Microsoft's current documentation on the day you build the firewall rule.
Where Studio helps
Studio's configuration generator produces a Direct Routing package for the SBC you run, from the same inputs as the call flow design, with the assumptions it made listed for review.