Skip to content

Microsoft Teams

The Thirdlane platform can integrate with Microsoft Teams and act as a Session Border Controller (SBC) for Direct Routing, connecting Teams calling to your own carriers and PSTN trunks. This lets organizations give Teams users a real phone number and full inbound/outbound PSTN calling through your existing Thirdlane trunks and routing - often at a lower cost and with more control than Microsoft’s Calling Plans - while calls between Teams users and the rest of your PBX (extensions, queues, IVRs) stay on-net. This screen configures the SBC side of that integration: the SIP signaling endpoint and the TLS certificates Microsoft requires to trust it.

To enable integration with Thirdlane all the MS Teams users will need to have Office 365 Enterprise E3 and Phone System License, or Office 365 Enterprise E5 license.

Microsoft Teams integration is a complex multi step process so we don’t recommend to do it alone without Microsoft Teams integration experience. Engaging Thirdlane support team is the best option.

You have to configure the integration on Microsoft web site, as well as in Thirdlane Configuration Manager.

If you don’t already have it, you will also have to obtain an SSL certificate. Note that if you are using Thirdlane Multi Tenant PBX you will need a wildcard certificate.

The certificate for Direct Routing is separate from every other certificate on the platform, and it has to be pasted in on this screen. It cannot be shared with the certificate under Domain and SSL Certificate or with SIP Encryption (TLS), and it cannot be a Let’s Encrypt certificate. Direct Routing is mutual TLS: your SBC presents a certificate to Microsoft to prove it is your SBC, and Microsoft requires that certificate to carry a capability called the Client Authentication extended key usage. Let’s Encrypt stopped issuing certificates with that capability during 2026, so a Let’s Encrypt certificate would work at first and could not be renewed into something Microsoft accepts. Buy the Direct Routing certificate from a commercial certificate authority, and replace it here before it expires - nothing renews it for you.

In Thirdlane, you will also have to specify whether the Microsoft Teams integration is available for individual tenants and enabled for individual users.

General Configuration

On Microsoft web site

If you already have base domain and users, add domain alias for the newly added Thirdlane domain for each user, otherwise, create users with the newly created Thirdlane domain. The screens below show you how to register a domain record following the Microsoft Teams documentation.

Adding MS Teams Domain

Here is how to add the domain:

Adding MS Teams Domain - step 2

The newly added domain must be verified, which requieres a few steps:

Verifying MS Teams Domain

Connecting DNS record
Verification using TXT record
Verification using TXT record completed

After the domain is added, an alias has to be configured.

Adding domain alias

On Windows Desktop with PowerShell

Install PowerShell modules

Install required PowerShell modules using the following commands:

Install-Module -Name PowerShellGet -Force -AllowClobber

Install-Module -Name MicrosoftTeams -Force -AllowClobber

Connect to MS Teams backend

$credentials=Get-Credential

Connect-MicrosoftTeams -Credential $credentials

backend 2

Configure SBC using PowerShell commands

New-CsOnlinePSTNGateway -Fqdn sbc.yourdomain.com -Enabled $true -SipSignalingPort 5062 -MaxConcurrentSessions 100 -ForwardCallHistory $false -ForwardPai $true

Configure outbound Calls from Teams

Run the following PowerShell command for each tenant, replacing tenant with the Thirdlane tenant name. On the legacy Single Tenant edition, run the command omitting tenant.

Set-CsOnlinePstnUsage -Identity Global -Usage @{Add=”Default”}

New-CsOnlineVoiceRoute -Identity "All" -NumberPattern ".*" -OnlinePstnGatewayList tenantx.sbc.yourdomain.com -Priority 0 -OnlinePstnUsages "Default"

Set-CsOnlineVoiceRoutingPolicy "Global" -OnlinePstnUsages "Default"

Setup a Normalization Rule for Outbound Dialing

$TCXExt = New-CsVoiceNormalizationRule -Parent Global -Name "All numbers" -Description "All numbers" -Pattern '^(\d+)$' -Translation '$1' -IsInternalExtension $false -InMemory

Set-CsTenantDialPlan -Identity "Global" -NormalizationRules @{add=$TCXExt}

In Configuration Manager

In Thirdlane Configuration Manager go to Communications Settings > Microsoft Teams screen and specify your Base Domain, SIP signaling Port for Direct Routing TLS connections, nsert your certificate, its key and a root certificate.

In addition to any other root certificates a ‘Baltimore CyberTrust Root’ certificate is required and has to be added to the Root Certificate section. This root certificate can be copied from here

System level configuration for MS Teams integration in Configuration Manager

Base Domain. Specify Base Domain.

Port. Specify SIP signaling port for Direct Routing SBC.

Endpoint TLS Connection Options. Specify your TLS protocol method choosing one of the options:

  • Accept only TLSv1.2 Connections
  • Accept TLSv1.1 or Newer Connections
  • Accept only TLSv1.1 Connections
  • Accept TLSv1.0 or Newer Connections
  • Accept only TLSv1 (TLSv1.0) Connections

Certificate. Copy your certificate here. This field is required for TLS transport.

Private Key. Copy your private key here. This field is required if TLS transport.

Root Certificate. Sets the root certificate (Certificate Authority). This field is required if TLS transport. It accepts multiple concatenated PEM certificates — paste the full set of Microsoft-required root CAs here (see the note above on the 2026 certificate authority change).

Require Certificate. When enabled, system will require a certificate from a client connecting to the TLS port. If the client does not offer a certificate, certificate verification will fail.

Verify Certificate. If enabled, it will force certificate verification when connecting to SIP endpoints.

Additional steps outside of Configuration Manager

In the system firewall configuration and on the external firewall (if your server is behind it) create a rule for the specified port.

In /etc/kamailio/local.cfg uncomment MS_TEAMS_FEATURE and restart Kamailio with “systemctl restart kamailio” (do not do this during working hours).

Tenant configuration for MS Teams integration

You have to configure and enable MS Teams for any Tenant that will be using it.

Configure MS Teams for Each User

In Thirdlane Configuration Manager

User Extension configuration for MS Teams integration

You also have to enable MS Teams for User Extensions.

In Microsoft Teams

Worked example: bring one Teams user online end to end

The sections above are grouped by where each step happens; this is the same work in the order you actually perform it, for a single SBC sbc.example.com on port 5062 serving tenant acme. Treat it as a checklist and read each section above for the detail.

  1. Microsoft 365 - domain. Add and verify your SBC/base domain (the TXT-record flow above), then give each Teams user an alias on that domain. Assign them the required E3 + Phone System or E5 licensing.
  2. PowerShell - SBC and routing. From the MicrosoftTeams module, register the gateway: New-CsOnlinePSTNGateway -Fqdn sbc.example.com -SipSignalingPort 5062 -Enabled $true -ForwardPai $true ..., then create the PSTN usage, voice route (pointing OnlinePstnGatewayList at your SBC FQDN), voice routing policy, and the outbound normalization rule shown above.
  3. Configuration Manager - SBC side. Under Communications Settings > Microsoft Teams, set Base Domain and Port 5062, choose “Accept only TLSv1.2 Connections”, and paste your Certificate, Private Key, and the full Root Certificate bundle (all Microsoft-required CAs from the 2026 note, plus Baltimore CyberTrust during the transition). Save - the platform writes the bundle and restarts the Teams SBC.
  4. Server - firewall and feature flag. Open port 5062 on the system firewall and any external firewall. Uncomment MS_TEAMS_FEATURE in /etc/kamailio/local.cfg and systemctl restart kamailio in a maintenance window.
  5. Enable per tenant, then per user. Enable Microsoft Teams for tenant acme, then enable it on each participating User Extension, and assign the voice routing policy to those users in Teams.
  6. Verify. Confirm a clean TLS handshake / SIP OPTIONS with sip.g1.pstnhub.microsoft.com:5061, check the root bundle count with grep -c "BEGIN CERTIFICATE" /var/kamailio-teamssbc/certificates/default/CA/cert.pem, then place a test PSTN call out from the Teams client and an inbound call to that user’s number through your Trunk.

Because this spans Microsoft 365, DNS, PowerShell, certificates, and firewalls, run it with Thirdlane support the first time rather than solo.

Best practices

  • Engage Thirdlane support. As noted above, Direct Routing is a multi-step integration spanning Microsoft 365, DNS, PowerShell, certificates, and firewall rules. Doing it with an experienced team is strongly recommended over going it alone.
  • Get the certificate right first. Microsoft validates the SBC over TLS, so the certificate must be valid, trusted, and match your SBC FQDN. On Thirdlane Multi Tenant systems this means a wildcard certificate. Keep the full set of required root CAs in the Root Certificate field (see the 2026 certificate-authority note above) so the connection keeps validating through Microsoft’s rollout.
  • Open the signaling port on every firewall. The Direct Routing SIP port you configure must be reachable end to end - both the system firewall and any external firewall in front of the server.
  • Restart Kamailio outside working hours. Enabling MS_TEAMS_FEATURE requires a Kamailio restart, which briefly disrupts SIP; schedule it in a maintenance window.
  • Verify with Microsoft’s test endpoint. A successful TLS handshake / SIP OPTIONS exchange with sip.g1.pstnhub.microsoft.com confirms the SBC trusts the correct CAs before you rely on it for live calls.
  • SIP Encryption (TLS) - background on the TLS certificate fields used here.
  • Trunks - the carrier trunks that carry PSTN calls to and from Teams users.
  • Domain and SSL Certificate - the certificate for the web interface and Connect, which Direct Routing does not use.