Skip to content

Microsoft Teams Direct Routing

8 min readUpdated: Sep 26, 2026
View as Markdown
  1. Overview & Architecture
  2. Business & Operational Significance
  3. 🎯 User Roles & Key Capabilities
  4. Visual Interface & Form Layout
  5. Field & Configuration Reference
  6. Kamailio & RTPEngine Direct Routing Mechanics
  7. Microsoft Teams Phone System Compliance & Certificates
  8. Security Best Practices & Operational Hardening
  9. Troubleshooting & Verification
  10. Glossary

In Ring2All SBC, the Microsoft Teams Direct Routing module (public.msteams_tenants) bridges Microsoft 365 Teams Phone System users directly with enterprise telephony infrastructure, internal Ring2All PBX extensions, and external PSTN wholesale carriers.

Operating as a Microsoft-certified Session Border Controller architecture, Ring2All SBC terminates high-security SIP-TLS signaling on port 5061 and anchors secure SRTP media, translating between Microsoft’s cloud voice infrastructure and standard SIP trunking environments.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Microsoft 365 Cloud β”‚ β”‚ Ring2All SBC Core β”‚
β”‚ β€’ Microsoft Teams Phone Clients β”‚ β”‚ β€’ Kamailio SIP-TLS Engine (5061) β”‚
β”‚ β€’ Microsoft SIP Proxy Clusters β”‚ β”‚ β€’ RTPEngine Media Relay (SRTP/RTP) β”‚
β”‚ (52.112.0.0/14, 52.120.0.0/14) β”‚ β”‚ β€’ Auto-Synced IP Address Group (20) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ β”‚
β”‚ SIP-TLS (Port 5061) + SRTP β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Ring2All SBC Perimeter β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β–Ό β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Ring2All PBX Cluster β”‚ β”‚ Wholesale PSTN Carriers β”‚
β”‚ β€’ Internal Extensions β”‚ β”‚ β€’ Outbound LCR Routes β”‚
β”‚ β€’ Call Queues & IVRs β”‚ β”‚ β€’ DID Inbound Ingress β”‚
β”‚ β€’ AI Voice Agents & RAG β”‚ β”‚ β€’ STIR/SHAKEN Attestation β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

  • Eliminate Costly Microsoft Calling Plans: Enables organizations to utilize their existing wholesale SIP trunks, local DIDs, and negotiated carrier rates instead of purchasing expensive per-user Microsoft Calling Plans.
  • Unified PBX and Teams Interoperability: Seamlessly joins Teams softphones with Ring2All PBX hardware deskphones, overhead paging systems, call center queues, and AI conversational agents.
  • Multi-Tenant Direct Routing: Service providers and ITSPs can host hundreds of independent Microsoft 365 customer tenants on a single shared Ring2All SBC cluster with isolated billing, routing tables, and security boundaries.
  • Automatic Survivability & Failover: If Microsoft’s cloud infrastructure experiences degradation, inbound customer calls can automatically failover to mobile phones, secondary data centers, or local analog/SIP gateways.

Role Primary Use Case Key Capabilities
SBC Administrator Enterprise Tenant Setup Provision Microsoft 365 Direct Routing tenants; assign commercial CA TLS certificates; manage trusted Microsoft IP address groups; configure dispatch routing sets.
Microsoft 365 Voice Engineer Voice Gateway Integration Verify SIP OPTIONS ping handshakes; validate Teams FQDN domain ownership; monitor SRTP media translation and MOS quality scores.
Carrier Operations (NOC) Peering & Quality Monitoring Monitor real-time Teams SIP ladders; diagnose TLS certificate chain issues; inspect codec negotiation (SILK, Opus, G.711u/a).

The list view provides an operational overview of all active Microsoft Teams tenants, showing assigned SBC FQDNs, signaling ports, media encryption modes, and operational status.

MS Teams Direct Routing List

The configuration form features structured sections for Tenant Identity, SBC Direct Routing Parameters, Trusted Microsoft IP Ranges, and Direct Routing Compliance Verification.

MS Teams Direct Routing Form


Section 1: Tenant Identity & Microsoft 365 Association

Section titled β€œSection 1: Tenant Identity & Microsoft 365 Association”
Field Type Constraints / Format Description
Tenant Name * Text Max 100 characters Human-readable corporate identifier for the organization (e.g., Ring2All Enterprise Teams).
Microsoft Tenant ID UUID Valid Microsoft 365 GUID The Azure Active Directory Directory ID (TenantId) associated with the client’s Microsoft 365 subscription.
Status * Dropdown active, suspended, maintenance Operational status of the Direct Routing tenant. Suspended tenants drop incoming SIP packets immediately.
Field Type Constraints / Format Description
SBC FQDN * Text Valid Public FQDN The public DNS hostname registered and validated in the Microsoft 365 Teams Admin Center (e.g., sbc.ring2all.com).
SIP Port * Number Default 5061 Ingress and egress signaling port. Microsoft Direct Routing strictly mandates port 5061 with TLS encryption.
Media Encryption * Dropdown SRTP (Mandatory) Cryptographic media security mode. Microsoft Direct Routing strictly enforces Secure Real-Time Transport Protocol (SRTP).
TLS Profile * Dropdown Valid Commercial TLS Profile The TLS profile referencing an authentic commercial certificate issued by a Microsoft-approved CA (DigiCert, Sectigo, etc.).
PBX Dispatch Set Dropdown Dispatcher Cluster ID Backend Telephony Server/PBX endpoint group designated to receive calls originating from this Teams tenant.
Failover Routing Toggle Boolean (Yes / No) Automatically reroutes inbound calls to designated secondary PSTN numbers if the Microsoft Teams SIP endpoint is unreachable.
Subnet CIDR Region / Role Auto-Sync Status Description
52.112.0.0/14 Global Primary Synchronized (Group 20) Worldwide Microsoft Teams SIP signaling proxies and media processors.
52.120.0.0/14 Global Secondary Synchronized (Group 20) Worldwide Microsoft Teams secondary voice routing clusters.
52.122.0.0/15 Expansion Voice Cloud Synchronized (Group 20) North American and European Teams Direct Routing points of presence.

When bridging sessions between Microsoft Teams and Ring2All PBX or PSTN carriers, the SBC performs automated protocol transformation:

  1. Bidirectional SIP OPTIONS Keep-Alive:
    • Kamailio periodically sends OPTIONS sip:sip.pstnhub.microsoft.com:5061 containing the custom user agent and supported codecs.
    • Microsoft answers with SIP 200 OK. If three consecutive heartbeats fail, the SBC marks the route degraded and activates failover.
  2. Contact Header Rewriting & Record-Route:
    • Microsoft Teams strictly checks that the domain in the Contact: header matches the validated SBC FQDN.
    • Kamailio rewrites the contact header:
      $ct = "<sip:" + $fU + "@" + $sel(cfg_get.msteams.sbc_fqdn) + ":5061;transport=tls>";
  3. Media Bridging with RTPEngine:
    • Microsoft Teams mandates SRTP with AES_CM_128_HMAC_SHA1_80 or AES_256_CM_HMAC_SHA1_80.
    • Backend PBX nodes and PSTN trunks frequently operate on standard unencrypted RTP.
    • RTPEngine performs zero-latency media transcoding and cryptographic unmasking:
      # Teams -> SBC -> PBX
      rtpengine_offer("RTP/AVP replace-origin replace-session-connection ICE=remove");
      # PBX -> SBC -> Teams
      rtpengine_answer("RTP/SAVP replace-origin replace-session-connection");

7. Microsoft Teams Phone System Compliance & Certificates

Section titled β€œ7. Microsoft Teams Phone System Compliance & Certificates”

To maintain seamless certification and connectivity with Microsoft Direct Routing:

  • Commercial CA Certificate Required: Microsoft PSTN Hubs will immediately terminate the TLS handshake if the SBC uses self-signed certificates or Let’s Encrypt certificates. You must deploy certificates from authorized roots:
    • DigiCert Global Root CA
    • Sectigo (Comodo)
    • GlobalSign
    • Entrust Datacard
  • Subject Alternative Names (SAN): The certificate’s Common Name (CN) or SAN must match the SBC FQDN configured in the Teams Admin Center exactly.
  • Firewall Ports Openings:
    • Inbound & Outbound TCP: 5061 (SIP-TLS) to Microsoft subnets.
    • Outbound UDP: 10000-20000 to 3478-3481, 49152-65535 for SRTP media.

  • Enforce Strict IP Whitelisting: Lock SIP port 5061 to exclusively accept connections from Kamailio Address Group 20 (Microsoft’s official IP ranges) using the Kamailio permissions module.
  • Prevent Toll Fraud on Failover: When failover routing is enabled, restrict failover destination numbers using Class of Service (CoS) dial rules to prevent unauthorized international forwarding.
  • Monitor SIP User-Agent Signatures: Validate that incoming INVITEs contain Microsoft’s signature headers (MS-CV - Correlation Vector).

Symptom / Issue Potential Root Cause Recommended Verification & Resolution
Teams Admin Center reports β€œSBC Inactive” TLS handshake failure or missing OPTIONS responses. Check TLS certificate expiration and verify that Kamailio is sending OPTIONS with commercial CA binding via kamcmd tls.list.
Calls dropped after 10 seconds (One-Way Audio) Firewall blocking UDP SRTP media or RTPEngine ICE mismatch. Ensure UDP ports 10000-20000 are forwarded to RTPEngine and review SDP media flags in Reports > SIP Traces.
Inbound calls from Teams fail with 403 Forbidden FQDN mismatch between Teams Admin Center and SBC domain record. Verify that the domain configured in SBC FQDN matches the tenant’s Microsoft voice gateway entry character-for-character.

  • Direct Routing: Microsoft Teams feature allowing enterprise customers to connect their own SBC and carrier voice trunks to Microsoft Teams Phone.
  • SRTP (Secure Real-time Transport Protocol): Encrypted profile of RTP providing confidentiality, message authentication, and replay protection for audio streams.
  • PSTN Hub: Microsoft cloud telephony proxy architecture (sip.pstnhub.microsoft.com) responsible for terminating Direct Routing carrier trunks.
  • OPTIONS Ping: Periodic SIP keep-alive message exchanged between SBC and Microsoft PSTN proxies to verify network latency and gateway health.