MS-721 · Question #102
You have a Microsoft Teams Phone deployment. You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You are signaling port 5067
The correct answer is B. The Baltimore or the Digicert root certificates are missing on the SBC.. Microsoft Teams Direct Routing requires the SBC to trust Microsoft's TLS certificates during the mutual TLS (mTLS) handshake. Microsoft uses certificates chained to specific root Certificate Authorities, including the Baltimore CyberTrust Root and DigiCert Global Root CA. If thes
Question
Options
- ACalling plan licenses are not assigned to users.
- BThe Baltimore or the Digicert root certificates are missing on the SBC.
- CThe Forward P-Asserted Identify (PAI) header is disabled.
- DThe failover timer is set to 0 seconds
How the community answered
(45 responses)- A11% (5)
- B82% (37)
- C4% (2)
- D2% (1)
Explanation
Microsoft Teams Direct Routing requires the SBC to trust Microsoft's TLS certificates during the mutual TLS (mTLS) handshake. Microsoft uses certificates chained to specific root Certificate Authorities, including the Baltimore CyberTrust Root and DigiCert Global Root CA. If these root certificates are not installed in the SBC's trusted certificate store, the TLS handshake fails and calls cannot be placed, which is exactly the error shown in the admin center. Calling plan licenses (A) are irrelevant in Direct Routing scenarios. The PAI header (C) affects caller identity but not connectivity. A failover timer of 0 seconds (D) would affect failover behavior, not initial call placement.
Topics
Community Discussion
No community discussion yet for this question.