Microsoft Teams Direct Routing: what the SBC has to do

Direct Routing connects Microsoft Teams to your own carrier through a session border controller you operate. Microsoft is strict about how that SBC identifies itself. Most failed first connections come down to one of the items below.

A name Microsoft can verify

A certificate that matches the name

Signaling

Media

Routing inside Teams

An SBC that shows as healthy still carries no calls until Teams is told to use it. That takes a voice route with a number pattern pointing at the SBC, a usage that groups routes, and a voice routing policy assigned to each user. Each user also needs a Microsoft Teams license with Teams Phone, and a phone number.

Check before the first call

  1. The public name resolves to the SBC's public address.
  2. The certificate is valid for that name, with its full chain installed.
  3. The SBC's OPTIONS messages are answered with 200 OK.
  4. The Teams admin center shows the SBC as active.
  5. A test user has a license, a number and a routing policy.
Address ranges and port ranges change. Read them from Microsoft's current documentation on the day you build the firewall rule.

Where Studio helps

Studio's configuration generator produces a Direct Routing package for the SBC you run, from the same inputs as the call flow design, with the assumptions it made listed for review.