Microsoft Teams
The Thirdlane platform can integrate with Microsoft Teams and act as a Session Border Controller (SBC) for Direct Routing, connecting Teams calling to your own carriers and PSTN trunks. This lets organizations give Teams users a real phone number and full inbound/outbound PSTN calling through your existing Thirdlane trunks and routing - often at a lower cost and with more control than Microsoft’s Calling Plans - while calls between Teams users and the rest of your PBX (extensions, queues, IVRs) stay on-net. This screen configures the SBC side of that integration: the SIP signaling endpoint and the TLS certificates Microsoft requires to trust it.
To enable integration with Thirdlane all the MS Teams users will need to have Office 365 Enterprise E3 and Phone System License, or Office 365 Enterprise E5 license.
Microsoft Teams integration is a complex multi step process so we don’t recommend to do it alone without Microsoft Teams integration experience. Engaging Thirdlane support team is the best option.
You have to configure the integration on Microsoft web site, as well as in Thirdlane Configuration Manager.
If you don’t already have it, you will also have to obtain an SSL certificate. Note that if you are using Thirdlane Multi Tenant PBX you will need a wildcard certificate.
The certificate for Direct Routing is separate from every other certificate on the platform, and it has to be pasted in on this screen. It cannot be shared with the certificate under Domain and SSL Certificate or with SIP Encryption (TLS), and it cannot be a Let’s Encrypt certificate. Direct Routing is mutual TLS: your SBC presents a certificate to Microsoft to prove it is your SBC, and Microsoft requires that certificate to carry a capability called the Client Authentication extended key usage. Let’s Encrypt stopped issuing certificates with that capability during 2026, so a Let’s Encrypt certificate would work at first and could not be renewed into something Microsoft accepts. Buy the Direct Routing certificate from a commercial certificate authority, and replace it here before it expires - nothing renews it for you.
In Thirdlane, you will also have to specify whether the Microsoft Teams integration is available for individual tenants and enabled for individual users.
General Configuration
On Microsoft web site
If you already have base domain and users, add domain alias for the newly added Thirdlane domain for each user, otherwise, create users with the newly created Thirdlane domain. The screens below show you how to register a domain record following the Microsoft Teams documentation.
Adding MS Teams Domain
Here is how to add the domain:
Adding MS Teams Domain - step 2
The newly added domain must be verified, which requieres a few steps:
Verifying MS Teams Domain
Connecting DNS record
Verification using TXT record
Verification using TXT record completed
After the domain is added, an alias has to be configured.
Adding domain alias
On Windows Desktop with PowerShell
Install PowerShell modules
Install required PowerShell modules using the following commands:
Install-Module -Name PowerShellGet -Force -AllowClobber
Install-Module -Name MicrosoftTeams -Force -AllowClobber
Connect to MS Teams backend
$credentials=Get-Credential
Connect-MicrosoftTeams -Credential $credentials
backend 2
Configure SBC using PowerShell commands
New-CsOnlinePSTNGateway -Fqdn sbc.yourdomain.com -Enabled $true -SipSignalingPort 5062 -MaxConcurrentSessions 100 -ForwardCallHistory $false -ForwardPai $true
Configure outbound Calls from Teams
Run the following PowerShell command for each tenant, replacing tenant with the Thirdlane tenant name. On the legacy Single Tenant edition, run the command omitting tenant.
Set-CsOnlinePstnUsage -Identity Global -Usage @{Add=”Default”}
New-CsOnlineVoiceRoute -Identity "All" -NumberPattern ".*" -OnlinePstnGatewayList tenantx.sbc.yourdomain.com -Priority 0 -OnlinePstnUsages "Default"
Set-CsOnlineVoiceRoutingPolicy "Global" -OnlinePstnUsages "Default"
Setup a Normalization Rule for Outbound Dialing
$TCXExt = New-CsVoiceNormalizationRule -Parent Global -Name "All numbers" -Description "All numbers" -Pattern '^(\d+)$' -Translation '$1' -IsInternalExtension $false -InMemory
Set-CsTenantDialPlan -Identity "Global" -NormalizationRules @{add=$TCXExt}
In Configuration Manager
In Thirdlane Configuration Manager go to Communications Settings > Microsoft Teams screen and specify your Base Domain, SIP signaling Port for Direct Routing TLS connections, nsert your certificate, its key and a root certificate.
In addition to any other root certificates a ‘Baltimore CyberTrust Root’ certificate is required and has to be added to the Root Certificate section. This root certificate can be copied from here
System level configuration for MS Teams integration in Configuration Manager
Base Domain. Specify Base Domain.
Port. Specify SIP signaling port for Direct Routing SBC.
Endpoint TLS Connection Options. Specify your TLS protocol method choosing one of the options:
- Accept only TLSv1.2 Connections
- Accept TLSv1.1 or Newer Connections
- Accept only TLSv1.1 Connections
- Accept TLSv1.0 or Newer Connections
- Accept only TLSv1 (TLSv1.0) Connections
Certificate. Copy your certificate here. This field is required for TLS transport.
Private Key. Copy your private key here. This field is required if TLS transport.
Root Certificate. Sets the root certificate (Certificate Authority). This field is required if TLS transport. It accepts multiple concatenated PEM certificates — paste the full set of Microsoft-required root CAs here (see the note above on the 2026 certificate authority change).
Require Certificate. When enabled, system will require a certificate from a client connecting to the TLS port. If the client does not offer a certificate, certificate verification will fail.
Verify Certificate. If enabled, it will force certificate verification when connecting to SIP endpoints.
Additional steps outside of Configuration Manager
In the system firewall configuration and on the external firewall (if your server is behind it) create a rule for the specified port.
In /etc/kamailio/local.cfg uncomment MS_TEAMS_FEATURE and restart Kamailio with “systemctl restart kamailio” (do not do this during working hours).
Tenant configuration for MS Teams integration
You have to configure and enable MS Teams for any Tenant that will be using it.
Configure MS Teams for Each User
In Thirdlane Configuration Manager
User Extension configuration for MS Teams integration
You also have to enable MS Teams for User Extensions.
In Microsoft Teams
Worked example: bring one Teams user online end to end
The sections above are grouped by where each step happens; this is the same work in the order you actually perform it, for a single SBC sbc.example.com on port 5062 serving tenant acme. Treat it as a checklist and read each section above for the detail.
- Microsoft 365 - domain. Add and verify your SBC/base domain (the TXT-record flow above), then give each Teams user an alias on that domain. Assign them the required E3 + Phone System or E5 licensing.
- PowerShell - SBC and routing. From the
MicrosoftTeamsmodule, register the gateway:New-CsOnlinePSTNGateway -Fqdn sbc.example.com -SipSignalingPort 5062 -Enabled $true -ForwardPai $true ..., then create the PSTN usage, voice route (pointingOnlinePstnGatewayListat your SBC FQDN), voice routing policy, and the outbound normalization rule shown above. - Configuration Manager - SBC side. Under Communications Settings > Microsoft Teams, set Base Domain and Port
5062, choose “Accept only TLSv1.2 Connections”, and paste your Certificate, Private Key, and the full Root Certificate bundle (all Microsoft-required CAs from the 2026 note, plus Baltimore CyberTrust during the transition). Save - the platform writes the bundle and restarts the Teams SBC. - Server - firewall and feature flag. Open port
5062on the system firewall and any external firewall. UncommentMS_TEAMS_FEATUREin/etc/kamailio/local.cfgandsystemctl restart kamailioin a maintenance window. - Enable per tenant, then per user. Enable Microsoft Teams for tenant
acme, then enable it on each participating User Extension, and assign the voice routing policy to those users in Teams. - Verify. Confirm a clean TLS handshake / SIP OPTIONS with
sip.g1.pstnhub.microsoft.com:5061, check the root bundle count withgrep -c "BEGIN CERTIFICATE" /var/kamailio-teamssbc/certificates/default/CA/cert.pem, then place a test PSTN call out from the Teams client and an inbound call to that user’s number through your Trunk.
Because this spans Microsoft 365, DNS, PowerShell, certificates, and firewalls, run it with Thirdlane support the first time rather than solo.
Best practices
- Engage Thirdlane support. As noted above, Direct Routing is a multi-step integration spanning Microsoft 365, DNS, PowerShell, certificates, and firewall rules. Doing it with an experienced team is strongly recommended over going it alone.
- Get the certificate right first. Microsoft validates the SBC over TLS, so the certificate must be valid, trusted, and match your SBC FQDN. On Thirdlane Multi Tenant systems this means a wildcard certificate. Keep the full set of required root CAs in the Root Certificate field (see the 2026 certificate-authority note above) so the connection keeps validating through Microsoft’s rollout.
- Open the signaling port on every firewall. The Direct Routing SIP port you configure must be reachable end to end - both the system firewall and any external firewall in front of the server.
- Restart Kamailio outside working hours. Enabling
MS_TEAMS_FEATURErequires a Kamailio restart, which briefly disrupts SIP; schedule it in a maintenance window. - Verify with Microsoft’s test endpoint. A successful TLS handshake / SIP OPTIONS exchange with
sip.g1.pstnhub.microsoft.comconfirms the SBC trusts the correct CAs before you rely on it for live calls.
Related documentation
- SIP Encryption (TLS) - background on the TLS certificate fields used here.
- Trunks - the carrier trunks that carry PSTN calls to and from Teams users.
- Domain and SSL Certificate - the certificate for the web interface and Connect, which Direct Routing does not use.