Microsoft Teams SIP Gateway: Onboarding Cisco 7800/8800 & AudioCodes 400HD (Intune, Conditional Access & Device Setup)

As organizations decommission legacy on-premises PBXs like Cisco Unified Communications Manager (CUCM) or Skype for Business Server, IT departments face a massive financial dilemma: what to do with thousands of functioning enterprise IP desk phones? Purchasing native Microsoft Teams Android desk phones costs anywhere from $250 to $600 per seat—a capital expenditure that can easily exceed hundreds of thousands of dollars.

The solution is the Microsoft Teams SIP Gateway. SIP Gateway enables core Microsoft Teams calling functionality on compatible third-party SIP hardware—most notably Cisco 7800/8800 series and AudioCodes 400HD series desk phones.

However, bringing these devices onto Teams is not a simple plug-and-play process. Success requires strict attention to firmware requirements, regional DHCP bootstrap endpoints, Teams Admin Center provisioning, and—most importantly—Microsoft Intune and Conditional Access policies that frequently block SIP phones from authenticating. This guide provides the complete, field-tested deployment runbook.

SIP Gateway Provisioning & Authentication Path:
Phone Boot ➔ DHCP Option 66 (HTTP Port 80) ➔ Microsoft Bootstrap Server ➔ Ingests Root CA & Config ➔ Upgrades to HTTPS (Port 443) ➔ TAC Verification Pairing (*55*Code) ➔ OAuth 2.0 Device Code Flow (microsoft.com/devicelogin) ➔ SIP over TLS (Port 5061) to Teams Cloud PBX

Phase 1: Licensing, Account Types & Teams Policy Prerequisites

1. User Account Licensing

For individual employee desk phones, the user account in Microsoft Entra ID must have:

• A base Microsoft 365 license (E3, E5, Business Premium, or Office 365 E1/E3).

• A Microsoft Teams Phone Standard add-on license (included automatically in Microsoft 365 E5).

• An assigned telephone number via Direct Routing, Operator Connect, or Microsoft Calling Plans with EnterpriseVoiceEnabled = $true.

2. Common Area / Shared Device Licensing

For shared phones deployed in lobbies, conference rooms, hallways, and manufacturing floors:

• Create a dedicated cloud-only user account in Entra ID (e.g., lobby-phone@contoso.com).

• Assign the Microsoft Teams Shared Devices license (formerly Common Area Phone / CAP license).

• No Exchange Online mailbox license is required for basic shared dial-pad functionality.

3. Enable SIP Gateway in Teams Calling Policy

By default, SIP Gateway calling is disabled in Microsoft Teams tenants. You must enable it in your global or custom Calling Policy:

# 1. Connect to Microsoft Teams PowerShell
Connect-MicrosoftTeams

# 2. Enable SIP devices globally across the tenant
Set-CsTeamsCallingPolicy -Identity "Global" -AllowSIPDevicesCalling $true

# 3. Verify policy settings
Get-CsTeamsCallingPolicy -Identity "Global" | Select-Object Identity, AllowSIPDevicesCalling

GUI Path: Teams Admin Center ➔ Voice ➔ Calling policies ➔ Toggle “SIP devices can be used for calls” to On.


Phase 2: Microsoft Intune & Conditional Access (CA) Configuration

Authentication failures during SIP Gateway onboarding almost always trace back to security policies blocking the device login flow.

1. The Intune Reality: SIP Devices Do NOT Enroll in MDM

Critical Architectural Principle:

Cisco MPP and AudioCodes 400HD phones are lightweight SIP endpoints. They cannot run the Microsoft Intune Company Portal app and cannot be enrolled into Microsoft Intune MDM. They connect purely via SIP signaling to Microsoft cloud SBCs.

If your organization enforces an Intune Enrollment Restriction (e.g., blocking personal or unknown device enrollment), or has a Conditional Access policy requiring “Require device to be marked as compliant”, the phone will fail to register. You must implement the following policy exclusions:

2. Conditional Access Exclusions for SIP Gateway

  1. Group Your SIP Phone Accounts: Create an Entra ID security group containing all common area phone identities and accounts assigned to desk phones (e.g., SG-Teams-SIPGateway-Devices).
  2. Exclude from Device Compliance Policies:
    • In the Microsoft Entra Admin Center, locate any Conditional Access policy that enforces “Require device to be marked as compliant” or “Require Microsoft Entra hybrid joined device”.
    • Under Users ➔ Exclude, add the SG-Teams-SIPGateway-Devices security group.
  3. Handling Multi-Factor Authentication (MFA):
    • SIP Gateway devices cannot perform interactive biometric or push MFA prompts on their dial pad.
    • Authentication is performed via the Device Code Flow (entering an 8-character code at https://microsoft.com/devicelogin). The administrator or user satisfies MFA inside their browser during initial pairing.
    • To prevent subsequent automated token refresh failures, configure a CA policy granting access to the SG-Teams-SIPGateway-Devices group based on Trusted Named Locations (your corporate office public egress IPs) rather than repetitive MFA challenges.

Phase 3: Network & DHCP Provisioning (Option 66 / 160)

When an unconfigured phone boots up, it looks for DHCP Option 66 (Boot Server Host Name) or Option 160 on the voice VLAN to locate its provisioning files:

Region / Geography Exact Provisioning Server URL (Port 80)
Americas (US, Canada, LATAM) http://usa.sip.teams.microsoft.com:80
EMEA (Europe, Middle East, Africa) http://emea.sip.teams.microsoft.com:80
APAC (Asia-Pacific, Australia) http://apac.sip.teams.microsoft.com:80

Network Port Requirements: Ensure perimeter firewalls allow outbound access from the Voice VLAN to Microsoft IP ranges for:

  • TCP Port 80 (HTTP): Initial unencrypted bootstrap connection (downloads Microsoft Root CAs).
  • TCP Port 443 (HTTPS): Secure provisioning and configuration XML downloads.
  • TCP Port 5061 (SIP-TLS): Encrypted SIP signaling to the Teams SIP Gateway.
  • UDP Ports 10000–20000: Bidirectional SRTP/RTP audio media streams.

Phase 4: Device-Side Step-by-Step Configuration

1. Cisco 7800 / 8800 Series Configuration

Prerequisite: Multiplatform (MPP / 3PCC) Firmware

Standard Cisco Enterprise firmware (designed for CUCM) will not boot on Teams SIP Gateway. The phone must run MPP firmware (e.g., sip88xx.11-3-7MPP.loads). Convert phones using Cisco conversion licenses (L-CP-E2M) and the Cisco Cloud Transition portal before onboarding.

Step A: Hardware Factory Reset

  1. Disconnect the PoE ethernet cable.
  2. Press and hold the # (Pound) key while plugging the PoE cable back in.
  3. Wait until the Headset, Mute, and Speaker LEDs flash amber in sequence, then release #.
  4. Immediately press the following keypad sequence: 1 2 3 4 5 6 7 8 9 * 0 #.
  5. The screen will display “Factory Resetting” and reboot.

Step B: Static WebGUI Provisioning (If not using DHCP Option 66)

  1. Find the phone’s IP address (Press Applications ➔ Status ➔ Network Status).
  2. Open a browser to: http://<phone-ip>/admin/advanced.
  3. Navigate to Voice ➔ Provisioning ➔ Configuration Profile.
  4. In the Profile Rule field, paste your regional bootstrap URL:
    http://usa.sip.teams.microsoft.com:80 (or emea / apac).
  5. Scroll to the bottom and click Submit All Changes.

2. AudioCodes 400HD Series (405HD, 445HD, 450HD) Configuration

Step A: Hardware Factory Reset

  1. Press the Menu key on the phone.
  2. Navigate to Administration ➔ Restore to Default.
  3. Enter the admin password (default is 1234 or admin).
  4. Confirm reset. The phone will reboot to factory defaults.

Step B: WebGUI Staging

  1. Access the phone’s IP address in your browser (Credentials: admin / 1234).
  2. Navigate to Management ➔ Auto Provisioning.
  3. Set Provisioning Method to HTTP.
  4. In the Configuration Server URL, enter:
    http://usa.sip.teams.microsoft.com:80 (or emea / apac).
  5. Click Submit and restart the device.

Phase 5: Teams Admin Center (TAC) Staging & Verification Workflow

Once the physical phones can reach Microsoft’s bootstrap server, an administrator must register the hardware MAC addresses inside the tenant:

Step-by-Step TAC Registration:
1. In the Microsoft Teams Admin Center, expand Teams devices ➔ SIP devices.
2. In the top toolbar, click Actions ➔ Provision devices.
3. Click Add MAC addresses:

   • Enter the 12-character MAC address without dashes or colons (e.g., 001EBD123456).

   • Select Vendor: Cisco or AudioCodes.

   • (Optional) Upload a CSV file for bulk multi-hundred device deployments.
4. Click Save. The device appears in the list with the status: Waiting for verification.
5. Select the newly added MAC address and click Generate verification code. A 6-digit code will appear (e.g., 491023).

Phase 6: Pairing & Device Sign-In (Completing Authentication)

With the verification code generated, complete the pairing sequence directly from the desk phone:

  1. Dial the Pairing Sequence: On the physical desk phone dial pad, lift the handset (or press speakerphone) and dial:

    *55*<Verification_Code>

    Example: *55*491023
  2. Read the Device Login Code: The SIP Gateway validates the MAC address and displays an 8-character pairing code on the phone screen (e.g., C7DF-89KL).
  3. Authenticate in Browser:

    • Open a web browser on a PC or smartphone and navigate to: https://microsoft.com/devicelogin

    • Enter the 8-character code displayed on the phone.

    • Sign in using the target employee’s Microsoft 365 credentials or the dedicated Common Area Phone service account (e.g., lobby-phone@contoso.com).
  4. Device Activation: Within 30 seconds of successful browser sign-in, the phone screen refreshes, displays the user’s name and telephone extension, and its status in TAC transitions to Healthy / Online.

Enterprise Voice & Endpoint Architecture

Migrating Thousands of Legacy Desk Phones to Microsoft Teams?

Our Microsoft-certified enterprise voice architects design zero-touch DHCP provisioning architectures, Cisco MPP conversion roadmaps, Conditional Access device bypasses, and multi-site SIP Gateway rollouts.

Frequently Asked Questions (FAQ)

Do Cisco and AudioCodes phones on SIP Gateway need to be enrolled in Microsoft Intune?

No. SIP Gateway devices are pure SIP endpoints that do not run an operating system capable of supporting the Intune Company Portal. They cannot be enrolled in Intune MDM. In fact, organizations must explicitly exclude SIP phone service accounts from Conditional Access policies that require compliant or hybrid-joined devices to prevent sign-in failures.

Can I onboard a Cisco 7800 or 8800 phone running Enterprise firmware to Teams?

No. Cisco Enterprise firmware (designed for Cisco CallManager) uses proprietary TFTP XML configuration protocols that cannot communicate with Microsoft Teams. Phones must be converted to Cisco Multiplatform Phone (MPP / 3PCC) firmware using Cisco conversion licenses before they can connect to the Teams SIP Gateway.

How does Multi-Factor Authentication (MFA) work on desk phones without touchscreens?

SIP Gateway uses the OAuth 2.0 Device Code Flow. When the phone initiates sign-in, it displays an 8-character code on its LCD screen. The administrator or user navigates to https://microsoft.com/devicelogin in a web browser, enters the code, and completes interactive MFA on their computer or mobile phone.

Why is DHCP Option 66 configured with HTTP (Port 80) instead of HTTPS?

Factory-reset legacy hardware does not have modern Microsoft intermediate root certificates pre-installed in its local firmware trust store. The initial HTTP port 80 connection is used strictly as an unencrypted bootstrap to push Microsoft’s Root CA certificate. Once installed, the phone automatically switches all subsequent provisioning and firmware traffic to secure HTTPS on port 443.


Related Microsoft Teams Devices & Infrastructure Guides

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *