Microsoft Teams Direct Routing
Table of Contents
Section titled βTable of Contentsβ- Overview & Architecture
- Business & Operational Significance
- π― User Roles & Key Capabilities
- Visual Interface & Form Layout
- Field & Configuration Reference
- Kamailio & RTPEngine Direct Routing Mechanics
- Microsoft Teams Phone System Compliance & Certificates
- Security Best Practices & Operational Hardening
- Troubleshooting & Verification
- Glossary
1. Overview & Architecture
Section titled β1. Overview & ArchitectureβIn Ring2All SBC, the Microsoft Teams Direct Routing module (public.msteams_tenants) bridges Microsoft 365 Teams Phone System users directly with enterprise telephony infrastructure, internal Ring2All PBX extensions, and external PSTN wholesale carriers.
Operating as a Microsoft-certified Session Border Controller architecture, Ring2All SBC terminates high-security SIP-TLS signaling on port 5061 and anchors secure SRTP media, translating between Microsoftβs cloud voice infrastructure and standard SIP trunking environments.
ββββββββββββββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββββββββββββββ Microsoft 365 Cloud β β Ring2All SBC Core ββ β’ Microsoft Teams Phone Clients β β β’ Kamailio SIP-TLS Engine (5061) ββ β’ Microsoft SIP Proxy Clusters β β β’ RTPEngine Media Relay (SRTP/RTP) ββ (52.112.0.0/14, 52.120.0.0/14) β β β’ Auto-Synced IP Address Group (20) βββββββββββββββββββββ¬ββββββββββββββββββββ ββββββββββββββββββββ¬ββββββββββββββββββββ β β β SIP-TLS (Port 5061) + SRTP β βββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββ β βΌ βββββββββββββββββββββββββββββββββββββ β Ring2All SBC Perimeter β βββββββββββββββββββ¬ββββββββββββββββββ β ββββββββββββββββββββββββββ΄βββββββββββββββββββββββββ βΌ βΌ βββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββ β Ring2All PBX Cluster β β Wholesale PSTN Carriers β β β’ Internal Extensions β β β’ Outbound LCR Routes β β β’ Call Queues & IVRs β β β’ DID Inbound Ingress β β β’ AI Voice Agents & RAG β β β’ STIR/SHAKEN Attestation β βββββββββββββββββββββββββββββ βββββββββββββββββββββββββββββ2. Business & Operational Significance
Section titled β2. Business & Operational Significanceβ- Eliminate Costly Microsoft Calling Plans: Enables organizations to utilize their existing wholesale SIP trunks, local DIDs, and negotiated carrier rates instead of purchasing expensive per-user Microsoft Calling Plans.
- Unified PBX and Teams Interoperability: Seamlessly joins Teams softphones with Ring2All PBX hardware deskphones, overhead paging systems, call center queues, and AI conversational agents.
- Multi-Tenant Direct Routing: Service providers and ITSPs can host hundreds of independent Microsoft 365 customer tenants on a single shared Ring2All SBC cluster with isolated billing, routing tables, and security boundaries.
- Automatic Survivability & Failover: If Microsoftβs cloud infrastructure experiences degradation, inbound customer calls can automatically failover to mobile phones, secondary data centers, or local analog/SIP gateways.
3. π― User Roles & Key Capabilities
Section titled β3. π― User Roles & Key Capabilitiesβ| Role | Primary Use Case | Key Capabilities |
|---|---|---|
| SBC Administrator | Enterprise Tenant Setup | Provision Microsoft 365 Direct Routing tenants; assign commercial CA TLS certificates; manage trusted Microsoft IP address groups; configure dispatch routing sets. |
| Microsoft 365 Voice Engineer | Voice Gateway Integration | Verify SIP OPTIONS ping handshakes; validate Teams FQDN domain ownership; monitor SRTP media translation and MOS quality scores. |
| Carrier Operations (NOC) | Peering & Quality Monitoring | Monitor real-time Teams SIP ladders; diagnose TLS certificate chain issues; inspect codec negotiation (SILK, Opus, G.711u/a). |
4. Visual Interface & Form Layout
Section titled β4. Visual Interface & Form LayoutβMS Teams Tenants List View
Section titled βMS Teams Tenants List ViewβThe list view provides an operational overview of all active Microsoft Teams tenants, showing assigned SBC FQDNs, signaling ports, media encryption modes, and operational status.

MS Teams Tenant Configuration Form
Section titled βMS Teams Tenant Configuration FormβThe configuration form features structured sections for Tenant Identity, SBC Direct Routing Parameters, Trusted Microsoft IP Ranges, and Direct Routing Compliance Verification.

5. Field & Configuration Reference
Section titled β5. Field & Configuration ReferenceβSection 1: Tenant Identity & Microsoft 365 Association
Section titled βSection 1: Tenant Identity & Microsoft 365 Associationβ| Field | Type | Constraints / Format | Description |
|---|---|---|---|
| Tenant Name * | Text | Max 100 characters | Human-readable corporate identifier for the organization (e.g., Ring2All Enterprise Teams). |
| Microsoft Tenant ID | UUID | Valid Microsoft 365 GUID | The Azure Active Directory Directory ID (TenantId) associated with the clientβs Microsoft 365 subscription. |
| Status * | Dropdown | active, suspended, maintenance |
Operational status of the Direct Routing tenant. Suspended tenants drop incoming SIP packets immediately. |
Section 2: SBC Configuration & Signaling Parameters
Section titled βSection 2: SBC Configuration & Signaling Parametersβ| Field | Type | Constraints / Format | Description |
|---|---|---|---|
| SBC FQDN * | Text | Valid Public FQDN | The public DNS hostname registered and validated in the Microsoft 365 Teams Admin Center (e.g., sbc.ring2all.com). |
| SIP Port * | Number | Default 5061 |
Ingress and egress signaling port. Microsoft Direct Routing strictly mandates port 5061 with TLS encryption. |
| Media Encryption * | Dropdown | SRTP (Mandatory) |
Cryptographic media security mode. Microsoft Direct Routing strictly enforces Secure Real-Time Transport Protocol (SRTP). |
| TLS Profile * | Dropdown | Valid Commercial TLS Profile | The TLS profile referencing an authentic commercial certificate issued by a Microsoft-approved CA (DigiCert, Sectigo, etc.). |
| PBX Dispatch Set | Dropdown | Dispatcher Cluster ID | Backend Telephony Server/PBX endpoint group designated to receive calls originating from this Teams tenant. |
| Failover Routing | Toggle | Boolean (Yes / No) |
Automatically reroutes inbound calls to designated secondary PSTN numbers if the Microsoft Teams SIP endpoint is unreachable. |
Section 3: Trusted Microsoft IP Ranges (In-Line Sync)
Section titled βSection 3: Trusted Microsoft IP Ranges (In-Line Sync)β| Subnet CIDR | Region / Role | Auto-Sync Status | Description |
|---|---|---|---|
52.112.0.0/14 |
Global Primary | Synchronized (Group 20) | Worldwide Microsoft Teams SIP signaling proxies and media processors. |
52.120.0.0/14 |
Global Secondary | Synchronized (Group 20) | Worldwide Microsoft Teams secondary voice routing clusters. |
52.122.0.0/15 |
Expansion Voice Cloud | Synchronized (Group 20) | North American and European Teams Direct Routing points of presence. |
6. Kamailio & RTPEngine Direct Routing Mechanics
Section titled β6. Kamailio & RTPEngine Direct Routing MechanicsβWhen bridging sessions between Microsoft Teams and Ring2All PBX or PSTN carriers, the SBC performs automated protocol transformation:
- Bidirectional SIP OPTIONS Keep-Alive:
- Kamailio periodically sends
OPTIONS sip:sip.pstnhub.microsoft.com:5061containing the custom user agent and supported codecs. - Microsoft answers with
SIP 200 OK. If three consecutive heartbeats fail, the SBC marks the route degraded and activates failover.
- Kamailio periodically sends
- Contact Header Rewriting & Record-Route:
- Microsoft Teams strictly checks that the domain in the
Contact:header matches the validated SBC FQDN. - Kamailio rewrites the contact header:
$ct = "<sip:" + $fU + "@" + $sel(cfg_get.msteams.sbc_fqdn) + ":5061;transport=tls>";
- Microsoft Teams strictly checks that the domain in the
- Media Bridging with RTPEngine:
- Microsoft Teams mandates SRTP with
AES_CM_128_HMAC_SHA1_80orAES_256_CM_HMAC_SHA1_80. - Backend PBX nodes and PSTN trunks frequently operate on standard unencrypted RTP.
- RTPEngine performs zero-latency media transcoding and cryptographic unmasking:
# Teams -> SBC -> PBXrtpengine_offer("RTP/AVP replace-origin replace-session-connection ICE=remove");# PBX -> SBC -> Teamsrtpengine_answer("RTP/SAVP replace-origin replace-session-connection");
- Microsoft Teams mandates SRTP with
7. Microsoft Teams Phone System Compliance & Certificates
Section titled β7. Microsoft Teams Phone System Compliance & CertificatesβTo maintain seamless certification and connectivity with Microsoft Direct Routing:
- Commercial CA Certificate Required: Microsoft PSTN Hubs will immediately terminate the TLS handshake if the SBC uses self-signed certificates or Letβs Encrypt certificates. You must deploy certificates from authorized roots:
- DigiCert Global Root CA
- Sectigo (Comodo)
- GlobalSign
- Entrust Datacard
- Subject Alternative Names (SAN): The certificateβs Common Name (CN) or SAN must match the SBC FQDN configured in the Teams Admin Center exactly.
- Firewall Ports Openings:
- Inbound & Outbound TCP:
5061(SIP-TLS) to Microsoft subnets. - Outbound UDP:
10000-20000to3478-3481,49152-65535for SRTP media.
- Inbound & Outbound TCP:
8. Security Best Practices & Operational Hardening
Section titled β8. Security Best Practices & Operational Hardeningβ- Enforce Strict IP Whitelisting: Lock SIP port
5061to exclusively accept connections from Kamailio Address Group20(Microsoftβs official IP ranges) using the Kamailiopermissionsmodule. - Prevent Toll Fraud on Failover: When failover routing is enabled, restrict failover destination numbers using Class of Service (CoS) dial rules to prevent unauthorized international forwarding.
- Monitor SIP User-Agent Signatures: Validate that incoming INVITEs contain Microsoftβs signature headers (
MS-CV- Correlation Vector).
9. Troubleshooting & Verification
Section titled β9. Troubleshooting & Verificationβ| Symptom / Issue | Potential Root Cause | Recommended Verification & Resolution |
|---|---|---|
| Teams Admin Center reports βSBC Inactiveβ | TLS handshake failure or missing OPTIONS responses. | Check TLS certificate expiration and verify that Kamailio is sending OPTIONS with commercial CA binding via kamcmd tls.list. |
| Calls dropped after 10 seconds (One-Way Audio) | Firewall blocking UDP SRTP media or RTPEngine ICE mismatch. | Ensure UDP ports 10000-20000 are forwarded to RTPEngine and review SDP media flags in Reports > SIP Traces. |
Inbound calls from Teams fail with 403 Forbidden |
FQDN mismatch between Teams Admin Center and SBC domain record. | Verify that the domain configured in SBC FQDN matches the tenantβs Microsoft voice gateway entry character-for-character. |
10. Glossary
Section titled β10. Glossaryβ- Direct Routing: Microsoft Teams feature allowing enterprise customers to connect their own SBC and carrier voice trunks to Microsoft Teams Phone.
- SRTP (Secure Real-time Transport Protocol): Encrypted profile of RTP providing confidentiality, message authentication, and replay protection for audio streams.
- PSTN Hub: Microsoft cloud telephony proxy architecture (
sip.pstnhub.microsoft.com) responsible for terminating Direct Routing carrier trunks. - OPTIONS Ping: Periodic SIP keep-alive message exchanged between SBC and Microsoft PSTN proxies to verify network latency and gateway health.

