Microsoft Teams SIP Gateway: Onboarding Cisco 7800/8800 & AudioCodes 400HD (Intune, Conditional Access & Device Setup)
As organizations decommission legacy on-premises PBXs like Cisco Unified Communications Manager (CUCM) or Skype for Business Server, IT departments face a massive financial dilemma: what to do with thousands of functioning enterprise IP desk phones? Purchasing native Microsoft Teams Android desk phones costs anywhere from $250 to $600 per seat—a capital expenditure that can easily exceed hundreds of thousands of dollars.
The solution is the Microsoft Teams SIP Gateway. SIP Gateway enables core Microsoft Teams calling functionality on compatible third-party SIP hardware—most notably Cisco 7800/8800 series and AudioCodes 400HD series desk phones.
However, bringing these devices onto Teams is not a simple plug-and-play process. Success requires strict attention to firmware requirements, regional DHCP bootstrap endpoints, Teams Admin Center provisioning, and—most importantly—Microsoft Intune and Conditional Access policies that frequently block SIP phones from authenticating. This guide provides the complete, field-tested deployment runbook.
Phone Boot ➔ DHCP Option 66 (HTTP Port 80) ➔ Microsoft Bootstrap Server ➔ Ingests Root CA & Config ➔ Upgrades to HTTPS (Port 443) ➔ TAC Verification Pairing (*55*Code) ➔ OAuth 2.0 Device Code Flow (microsoft.com/devicelogin) ➔ SIP over TLS (Port 5061) to Teams Cloud PBX
Phase 1: Licensing, Account Types & Teams Policy Prerequisites
1. User Account Licensing
For individual employee desk phones, the user account in Microsoft Entra ID must have:
• A base Microsoft 365 license (E3, E5, Business Premium, or Office 365 E1/E3).
• A Microsoft Teams Phone Standard add-on license (included automatically in Microsoft 365 E5).
• An assigned telephone number via Direct Routing, Operator Connect, or Microsoft Calling Plans with EnterpriseVoiceEnabled = $true.
2. Common Area / Shared Device Licensing
For shared phones deployed in lobbies, conference rooms, hallways, and manufacturing floors:
• Create a dedicated cloud-only user account in Entra ID (e.g., lobby-phone@contoso.com).
• Assign the Microsoft Teams Shared Devices license (formerly Common Area Phone / CAP license).
• No Exchange Online mailbox license is required for basic shared dial-pad functionality.
3. Enable SIP Gateway in Teams Calling Policy
By default, SIP Gateway calling is disabled in Microsoft Teams tenants. You must enable it in your global or custom Calling Policy:
# 1. Connect to Microsoft Teams PowerShell
Connect-MicrosoftTeams
# 2. Enable SIP devices globally across the tenant
Set-CsTeamsCallingPolicy -Identity "Global" -AllowSIPDevicesCalling $true
# 3. Verify policy settings
Get-CsTeamsCallingPolicy -Identity "Global" | Select-Object Identity, AllowSIPDevicesCalling
GUI Path: Teams Admin Center ➔ Voice ➔ Calling policies ➔ Toggle “SIP devices can be used for calls” to On.
Phase 2: Microsoft Intune & Conditional Access (CA) Configuration
Authentication failures during SIP Gateway onboarding almost always trace back to security policies blocking the device login flow.
1. The Intune Reality: SIP Devices Do NOT Enroll in MDM
Critical Architectural Principle:
Cisco MPP and AudioCodes 400HD phones are lightweight SIP endpoints. They cannot run the Microsoft Intune Company Portal app and cannot be enrolled into Microsoft Intune MDM. They connect purely via SIP signaling to Microsoft cloud SBCs.
If your organization enforces an Intune Enrollment Restriction (e.g., blocking personal or unknown device enrollment), or has a Conditional Access policy requiring “Require device to be marked as compliant”, the phone will fail to register. You must implement the following policy exclusions:
2. Conditional Access Exclusions for SIP Gateway
- Group Your SIP Phone Accounts: Create an Entra ID security group containing all common area phone identities and accounts assigned to desk phones (e.g.,
SG-Teams-SIPGateway-Devices). - Exclude from Device Compliance Policies:
- In the Microsoft Entra Admin Center, locate any Conditional Access policy that enforces “Require device to be marked as compliant” or “Require Microsoft Entra hybrid joined device”.
- Under Users ➔ Exclude, add the
SG-Teams-SIPGateway-Devicessecurity group.
- Handling Multi-Factor Authentication (MFA):
- SIP Gateway devices cannot perform interactive biometric or push MFA prompts on their dial pad.
- Authentication is performed via the Device Code Flow (entering an 8-character code at
https://microsoft.com/devicelogin). The administrator or user satisfies MFA inside their browser during initial pairing. - To prevent subsequent automated token refresh failures, configure a CA policy granting access to the
SG-Teams-SIPGateway-Devicesgroup based on Trusted Named Locations (your corporate office public egress IPs) rather than repetitive MFA challenges.
Phase 3: Network & DHCP Provisioning (Option 66 / 160)
When an unconfigured phone boots up, it looks for DHCP Option 66 (Boot Server Host Name) or Option 160 on the voice VLAN to locate its provisioning files:
| Region / Geography | Exact Provisioning Server URL (Port 80) |
|---|---|
| Americas (US, Canada, LATAM) | http://usa.sip.teams.microsoft.com:80 |
| EMEA (Europe, Middle East, Africa) | http://emea.sip.teams.microsoft.com:80 |
| APAC (Asia-Pacific, Australia) | http://apac.sip.teams.microsoft.com:80 |
Network Port Requirements: Ensure perimeter firewalls allow outbound access from the Voice VLAN to Microsoft IP ranges for:
- TCP Port 80 (HTTP): Initial unencrypted bootstrap connection (downloads Microsoft Root CAs).
- TCP Port 443 (HTTPS): Secure provisioning and configuration XML downloads.
- TCP Port 5061 (SIP-TLS): Encrypted SIP signaling to the Teams SIP Gateway.
- UDP Ports 10000–20000: Bidirectional SRTP/RTP audio media streams.
Phase 4: Device-Side Step-by-Step Configuration
1. Cisco 7800 / 8800 Series Configuration
Prerequisite: Multiplatform (MPP / 3PCC) Firmware
Standard Cisco Enterprise firmware (designed for CUCM) will not boot on Teams SIP Gateway. The phone must run MPP firmware (e.g., sip88xx.11-3-7MPP.loads). Convert phones using Cisco conversion licenses (L-CP-E2M) and the Cisco Cloud Transition portal before onboarding.
Step A: Hardware Factory Reset
- Disconnect the PoE ethernet cable.
- Press and hold the # (Pound) key while plugging the PoE cable back in.
- Wait until the Headset, Mute, and Speaker LEDs flash amber in sequence, then release #.
- Immediately press the following keypad sequence:
1 2 3 4 5 6 7 8 9 * 0 #. - The screen will display “Factory Resetting” and reboot.
Step B: Static WebGUI Provisioning (If not using DHCP Option 66)
- Find the phone’s IP address (Press Applications ➔ Status ➔ Network Status).
- Open a browser to:
http://<phone-ip>/admin/advanced. - Navigate to Voice ➔ Provisioning ➔ Configuration Profile.
- In the Profile Rule field, paste your regional bootstrap URL:
http://usa.sip.teams.microsoft.com:80(oremea/apac). - Scroll to the bottom and click Submit All Changes.
2. AudioCodes 400HD Series (405HD, 445HD, 450HD) Configuration
Step A: Hardware Factory Reset
- Press the Menu key on the phone.
- Navigate to Administration ➔ Restore to Default.
- Enter the admin password (default is
1234oradmin). - Confirm reset. The phone will reboot to factory defaults.
Step B: WebGUI Staging
- Access the phone’s IP address in your browser (Credentials:
admin/1234). - Navigate to Management ➔ Auto Provisioning.
- Set Provisioning Method to
HTTP. - In the Configuration Server URL, enter:
http://usa.sip.teams.microsoft.com:80(oremea/apac). - Click Submit and restart the device.
Phase 5: Teams Admin Center (TAC) Staging & Verification Workflow
Once the physical phones can reach Microsoft’s bootstrap server, an administrator must register the hardware MAC addresses inside the tenant:
• Enter the 12-character MAC address without dashes or colons (e.g.,
001EBD123456).• Select Vendor: Cisco or AudioCodes.
• (Optional) Upload a CSV file for bulk multi-hundred device deployments.
491023).Phase 6: Pairing & Device Sign-In (Completing Authentication)
With the verification code generated, complete the pairing sequence directly from the desk phone:
- Dial the Pairing Sequence: On the physical desk phone dial pad, lift the handset (or press speakerphone) and dial:
*55*<Verification_Code>
Example:*55*491023 - Read the Device Login Code: The SIP Gateway validates the MAC address and displays an 8-character pairing code on the phone screen (e.g.,
C7DF-89KL). - Authenticate in Browser:
• Open a web browser on a PC or smartphone and navigate to:https://microsoft.com/devicelogin
• Enter the 8-character code displayed on the phone.
• Sign in using the target employee’s Microsoft 365 credentials or the dedicated Common Area Phone service account (e.g.,lobby-phone@contoso.com). - Device Activation: Within 30 seconds of successful browser sign-in, the phone screen refreshes, displays the user’s name and telephone extension, and its status in TAC transitions to Healthy / Online.
Migrating Thousands of Legacy Desk Phones to Microsoft Teams?
Our Microsoft-certified enterprise voice architects design zero-touch DHCP provisioning architectures, Cisco MPP conversion roadmaps, Conditional Access device bypasses, and multi-site SIP Gateway rollouts.
Frequently Asked Questions (FAQ)
Do Cisco and AudioCodes phones on SIP Gateway need to be enrolled in Microsoft Intune?
No. SIP Gateway devices are pure SIP endpoints that do not run an operating system capable of supporting the Intune Company Portal. They cannot be enrolled in Intune MDM. In fact, organizations must explicitly exclude SIP phone service accounts from Conditional Access policies that require compliant or hybrid-joined devices to prevent sign-in failures.
Can I onboard a Cisco 7800 or 8800 phone running Enterprise firmware to Teams?
No. Cisco Enterprise firmware (designed for Cisco CallManager) uses proprietary TFTP XML configuration protocols that cannot communicate with Microsoft Teams. Phones must be converted to Cisco Multiplatform Phone (MPP / 3PCC) firmware using Cisco conversion licenses before they can connect to the Teams SIP Gateway.
How does Multi-Factor Authentication (MFA) work on desk phones without touchscreens?
SIP Gateway uses the OAuth 2.0 Device Code Flow. When the phone initiates sign-in, it displays an 8-character code on its LCD screen. The administrator or user navigates to https://microsoft.com/devicelogin in a web browser, enters the code, and completes interactive MFA on their computer or mobile phone.
Why is DHCP Option 66 configured with HTTP (Port 80) instead of HTTPS?
Factory-reset legacy hardware does not have modern Microsoft intermediate root certificates pre-installed in its local firmware trust store. The initial HTTP port 80 connection is used strictly as an unencrypted bootstrap to push Microsoft’s Root CA certificate. Once installed, the phone automatically switches all subsequent provisioning and firmware traffic to secure HTTPS on port 443.
Related Microsoft Teams Devices & Infrastructure Guides
- Microsoft Teams Rooms (MTR) Setup: Step-by-Step Exchange Online, CA & Console Guide
- Cisco Webex Room Kit Integration with Microsoft Teams: Direct Guest Join (WebRTC) Setup
- How to Configure AudioCodes SBC for Microsoft Teams Direct Routing
- Ribbon SBC 1000/2000 Teams Direct Routing Step-by-Step Configuration
- Microsoft Teams Call Queues & Auto Attendants: Complete Setup Guide
- Teams Direct Routing SIP 403 Forbidden: User Licensing & FQDN Gotchas
- Teams Survivable Branch Appliance (SBA) Deployment & Branch Resiliency
- Teams Dynamic Emergency Calling (E911): RAY BAUM’S Act & Compliance