MS-721 · Question #55
You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named sbc.voice.contos
The correct answer is A. The certificate does not match the FQDN on the SBC.. In Microsoft Teams Direct Routing, the SBC must present a valid TLS certificate whose Subject Name (SN) or Subject Alternative Name (SAN) exactly matches the SBC's FQDN (sbc.voice.contoso.com). A certificate mismatch - for example, a certificate issued for a different domain or a
Question
Exhibit
Options
- AThe certificate does not match the FQDN on the SBC.
- BThe firewall blocks inbound traffic on port 443 to the SBC.
- COnly TLS 1.0 is enabled on the SBC.
- DMicrosoft 365 Phone System licenses are not assigned to the users.
How the community answered
(33 responses)- A82% (27)
- B3% (1)
- C12% (4)
- D3% (1)
Explanation
In Microsoft Teams Direct Routing, the SBC must present a valid TLS certificate whose Subject Name (SN) or Subject Alternative Name (SAN) exactly matches the SBC's FQDN (sbc.voice.contoso.com). A certificate mismatch - for example, a certificate issued for a different domain or a wildcard that doesn't cover the SBC's FQDN - causes Microsoft 365 to reject the TLS handshake and logs a certificate warning on the SBC. Port 443 (B) is used for Teams client traffic, not SBC signaling (which uses 5061). Teams Direct Routing requires TLS 1.2 minimum, so TLS 1.0-only (C) would cause a failure but typically a different error. Missing Phone System licenses (D) would block user calls, not generate an SBC certificate warning.
Topics
Community Discussion
No community discussion yet for this question.
