nerdexam
Microsoft

MS-720 · Question #134

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You are signaling port…

The correct answer is A. The Forward P-Asserted Identify (PAI) header is disabled. P-Asserted-Identity (PAI) is a SIP header that the SBC uses to convey the authenticated caller identity to Microsoft Teams. When PAI forwarding is disabled, Teams cannot verify who is placing the call, causing call failures that surface as an error in the Teams admin center…

Plan and configure Direct Routing

Question

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You are signaling port 5067. You cannot place calls and receive an error message in the Microsoft Teams admin center as shown in the following exhibit. What is a possible cause of the issue?

Exhibit

MS-720 question #134 exhibit

Options

  • AThe Forward P-Asserted Identify (PAI) header is disabled.
  • BLicenses are not assigned to the contoso.com domain.
  • CThe Baltimore root certificate is missing on the SBC.
  • DThe failover timer is set to 0 seconds.

How the community answered

(43 responses)
  • A
    72% (31)
  • B
    9% (4)
  • C
    16% (7)
  • D
    2% (1)

Explanation

P-Asserted-Identity (PAI) is a SIP header that the SBC uses to convey the authenticated caller identity to Microsoft Teams. When PAI forwarding is disabled, Teams cannot verify who is placing the call, causing call failures that surface as an error in the Teams admin center - this is a mandatory configuration requirement for Direct Routing. Option B is wrong because licenses are assigned to users, not domains, and a licensing issue would block users broadly, not produce an SBC signaling error. Option C is incorrect because a missing Baltimore root certificate would cause a TLS handshake failure, not a PAI-related signaling problem; and as of 2025, Microsoft has largely migrated away from the Baltimore CyberTrust Root anyway. Option D is wrong because a failover timer of 0 affects redundancy behavior, not whether an active SBC can establish calls.

Memory tip: Think of PAI as Teams asking the SBC "Who are you calling from?" - if the SBC is silent (PAI disabled), Teams refuses to connect the call. Always verify PAI forwarding is enabled on the SBC when troubleshooting Direct Routing call failures.

Topics

#Direct Routing#Session Border Controller (SBC)#SIP Headers#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full MS-720 Practice