--- title: "Microsoft Teams Direct Routing" description: "Documentation for MS Teams Direct Routing" --- ## Table of Contents 1. [Overview & Architecture](#1-overview--architecture) 2. [Business & Operational Significance](#2-business--operational-significance) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Form Layout](#4-visual-interface--form-layout) 5. [Field & Configuration Reference](#5-field--configuration-reference) 6. [Kamailio & RTPEngine Direct Routing Mechanics](#6-kamailio--rtpengine-direct-routing-mechanics) 7. [Microsoft Teams Phone System Compliance & Certificates](#7-microsoft-teams-phone-system-compliance--certificates) 8. [Security Best Practices & Operational Hardening](#8-security-best-practices--operational-hardening) 9. [Troubleshooting & Verification](#9-troubleshooting--verification) 10. [Glossary](#10-glossary) --- ## 1. Overview & Architecture In **Ring2All SBC**, the **Microsoft Teams Direct Routing** module (`public.msteams_tenants`) bridges Microsoft 365 Teams Phone System users directly with enterprise telephony infrastructure, internal **Ring2All PBX** extensions, and external PSTN wholesale carriers. Operating as a Microsoft-certified Session Border Controller architecture, Ring2All SBC terminates high-security **SIP-TLS** signaling on port 5061 and anchors secure **SRTP** media, translating between Microsoft's cloud voice infrastructure and standard SIP trunking environments. ``` ┌──────────────────────────────────────┐ ┌──────────────────────────────────────┐ │ Microsoft 365 Cloud │ │ Ring2All SBC Core │ │ • Microsoft Teams Phone Clients │ │ • Kamailio SIP-TLS Engine (5061) │ │ • Microsoft SIP Proxy Clusters │ │ • RTPEngine Media Relay (SRTP/RTP) │ │ (52.112.0.0/14, 52.120.0.0/14) │ │ • Auto-Synced IP Address Group (20) │ └──────────────────┬───────────────────┘ └──────────────────┬───────────────────┘ │ │ │ SIP-TLS (Port 5061) + SRTP │ └───────────────────────────┬────────────────────────┘ │ ▼ ┌───────────────────────────────────┐ │ Ring2All SBC Perimeter │ └─────────────────┬─────────────────┘ │ ┌────────────────────────┴────────────────────────┐ ▼ ▼ ┌───────────────────────────┐ ┌───────────────────────────┐ │ Ring2All PBX Cluster │ │ Wholesale PSTN Carriers │ │ • Internal Extensions │ │ • Outbound LCR Routes │ │ • Call Queues & IVRs │ │ • DID Inbound Ingress │ │ • AI Voice Agents & RAG │ │ • STIR/SHAKEN Attestation │ └───────────────────────────┘ └───────────────────────────┘ ``` --- ## 2. Business & Operational Significance * **Eliminate Costly Microsoft Calling Plans**: Enables organizations to utilize their existing wholesale SIP trunks, local DIDs, and negotiated carrier rates instead of purchasing expensive per-user Microsoft Calling Plans. * **Unified PBX and Teams Interoperability**: Seamlessly joins Teams softphones with Ring2All PBX hardware deskphones, overhead paging systems, call center queues, and AI conversational agents. * **Multi-Tenant Direct Routing**: Service providers and ITSPs can host hundreds of independent Microsoft 365 customer tenants on a single shared Ring2All SBC cluster with isolated billing, routing tables, and security boundaries. * **Automatic Survivability & Failover**: If Microsoft's cloud infrastructure experiences degradation, inbound customer calls can automatically failover to mobile phones, secondary data centers, or local analog/SIP gateways. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Primary Use Case | Key Capabilities | | :--- | :--- | :--- | | **SBC Administrator** | Enterprise Tenant Setup | Provision Microsoft 365 Direct Routing tenants; assign commercial CA TLS certificates; manage trusted Microsoft IP address groups; configure dispatch routing sets. | | **Microsoft 365 Voice Engineer** | Voice Gateway Integration | Verify SIP OPTIONS ping handshakes; validate Teams FQDN domain ownership; monitor SRTP media translation and MOS quality scores. | | **Carrier Operations (NOC)** | Peering & Quality Monitoring | Monitor real-time Teams SIP ladders; diagnose TLS certificate chain issues; inspect codec negotiation (SILK, Opus, G.711u/a). | --- ## 4. Visual Interface & Form Layout ### MS Teams Tenants List View The list view provides an operational overview of all active Microsoft Teams tenants, showing assigned SBC FQDNs, signaling ports, media encryption modes, and operational status. ![MS Teams Direct Routing List](/screenshots/sbc/routing/msteams/msteams-list.png) ### MS Teams Tenant Configuration Form The configuration form features structured sections for **Tenant Identity**, **SBC Direct Routing Parameters**, **Trusted Microsoft IP Ranges**, and **Direct Routing Compliance Verification**. ![MS Teams Direct Routing Form](/screenshots/sbc/routing/msteams/msteams-form.png) --- ## 5. Field & Configuration Reference ### Section 1: Tenant Identity & Microsoft 365 Association | Field | Type | Constraints / Format | Description | | :--- | :--- | :--- | :--- | | **Tenant Name \*** | Text | Max 100 characters | Human-readable corporate identifier for the organization (e.g., `Ring2All Enterprise Teams`). | | **Microsoft Tenant ID** | UUID | Valid Microsoft 365 GUID | The Azure Active Directory Directory ID (`TenantId`) associated with the client's Microsoft 365 subscription. | | **Status \*** | Dropdown | `active`, `suspended`, `maintenance` | Operational status of the Direct Routing tenant. Suspended tenants drop incoming SIP packets immediately. | ### Section 2: SBC Configuration & Signaling Parameters | Field | Type | Constraints / Format | Description | | :--- | :--- | :--- | :--- | | **SBC FQDN \*** | Text | Valid Public FQDN | The public DNS hostname registered and validated in the Microsoft 365 Teams Admin Center (e.g., `sbc.ring2all.com`). | | **SIP Port \*** | Number | Default `5061` | Ingress and egress signaling port. Microsoft Direct Routing strictly mandates port `5061` with TLS encryption. | | **Media Encryption \*** | Dropdown | `SRTP` (Mandatory) | Cryptographic media security mode. Microsoft Direct Routing strictly enforces Secure Real-Time Transport Protocol (`SRTP`). | | **TLS Profile \*** | Dropdown | Valid Commercial TLS Profile | The TLS profile referencing an authentic commercial certificate issued by a Microsoft-approved CA (DigiCert, Sectigo, etc.). | | **PBX Dispatch Set** | Dropdown | Dispatcher Cluster ID | Backend Telephony Server/PBX endpoint group designated to receive calls originating from this Teams tenant. | | **Failover Routing** | Toggle | Boolean (`Yes` / `No`) | Automatically reroutes inbound calls to designated secondary PSTN numbers if the Microsoft Teams SIP endpoint is unreachable. | ### Section 3: Trusted Microsoft IP Ranges (In-Line Sync) | Subnet CIDR | Region / Role | Auto-Sync Status | Description | | :--- | :--- | :--- | :--- | | `52.112.0.0/14` | Global Primary | Synchronized (Group 20) | Worldwide Microsoft Teams SIP signaling proxies and media processors. | | `52.120.0.0/14` | Global Secondary | Synchronized (Group 20) | Worldwide Microsoft Teams secondary voice routing clusters. | | `52.122.0.0/15` | Expansion Voice Cloud | Synchronized (Group 20) | North American and European Teams Direct Routing points of presence. | --- ## 6. Kamailio & RTPEngine Direct Routing Mechanics When bridging sessions between Microsoft Teams and Ring2All PBX or PSTN carriers, the SBC performs automated protocol transformation: 1. **Bidirectional SIP OPTIONS Keep-Alive**: - Kamailio periodically sends `OPTIONS sip:sip.pstnhub.microsoft.com:5061` containing the custom user agent and supported codecs. - Microsoft answers with `SIP 200 OK`. If three consecutive heartbeats fail, the SBC marks the route degraded and activates failover. 2. **Contact Header Rewriting & Record-Route**: - Microsoft Teams strictly checks that the domain in the `Contact:` header matches the validated SBC FQDN. - Kamailio rewrites the contact header: ```kamailio $ct = ""; ``` 3. **Media Bridging with RTPEngine**: - Microsoft Teams mandates **SRTP** with `AES_CM_128_HMAC_SHA1_80` or `AES_256_CM_HMAC_SHA1_80`. - Backend PBX nodes and PSTN trunks frequently operate on standard unencrypted **RTP**. - RTPEngine performs zero-latency media transcoding and cryptographic unmasking: ```kamailio # Teams -> SBC -> PBX rtpengine_offer("RTP/AVP replace-origin replace-session-connection ICE=remove"); # PBX -> SBC -> Teams rtpengine_answer("RTP/SAVP replace-origin replace-session-connection"); ``` --- ## 7. Microsoft Teams Phone System Compliance & Certificates To maintain seamless certification and connectivity with Microsoft Direct Routing: * **Commercial CA Certificate Required**: Microsoft PSTN Hubs will immediately terminate the TLS handshake if the SBC uses self-signed certificates or Let's Encrypt certificates. You must deploy certificates from authorized roots: - DigiCert Global Root CA - Sectigo (Comodo) - GlobalSign - Entrust Datacard * **Subject Alternative Names (SAN)**: The certificate's Common Name (CN) or SAN must match the **SBC FQDN** configured in the Teams Admin Center exactly. * **Firewall Ports Openings**: - Inbound & Outbound TCP: `5061` (SIP-TLS) to Microsoft subnets. - Outbound UDP: `10000-20000` to `3478-3481`, `49152-65535` for SRTP media. --- ## 8. Security Best Practices & Operational Hardening * **Enforce Strict IP Whitelisting**: Lock SIP port `5061` to exclusively accept connections from Kamailio Address Group `20` (Microsoft's official IP ranges) using the Kamailio `permissions` module. * **Prevent Toll Fraud on Failover**: When failover routing is enabled, restrict failover destination numbers using **Class of Service (CoS)** dial rules to prevent unauthorized international forwarding. * **Monitor SIP User-Agent Signatures**: Validate that incoming INVITEs contain Microsoft's signature headers (`MS-CV` - Correlation Vector). --- ## 9. Troubleshooting & Verification | Symptom / Issue | Potential Root Cause | Recommended Verification & Resolution | | :--- | :--- | :--- | | **Teams Admin Center reports "SBC Inactive"** | TLS handshake failure or missing OPTIONS responses. | Check TLS certificate expiration and verify that Kamailio is sending OPTIONS with commercial CA binding via `kamcmd tls.list`. | | **Calls dropped after 10 seconds (One-Way Audio)** | Firewall blocking UDP SRTP media or RTPEngine ICE mismatch. | Ensure UDP ports `10000-20000` are forwarded to RTPEngine and review SDP media flags in **Reports > SIP Traces**. | | **Inbound calls from Teams fail with `403 Forbidden`** | FQDN mismatch between Teams Admin Center and SBC domain record. | Verify that the domain configured in **SBC FQDN** matches the tenant's Microsoft voice gateway entry character-for-character. | --- ## 10. Glossary * **Direct Routing**: Microsoft Teams feature allowing enterprise customers to connect their own SBC and carrier voice trunks to Microsoft Teams Phone. * **SRTP (Secure Real-time Transport Protocol)**: Encrypted profile of RTP providing confidentiality, message authentication, and replay protection for audio streams. * **PSTN Hub**: Microsoft cloud telephony proxy architecture (`sip.pstnhub.microsoft.com`) responsible for terminating Direct Routing carrier trunks. * **OPTIONS Ping**: Periodic SIP keep-alive message exchanged between SBC and Microsoft PSTN proxies to verify network latency and gateway health.