AudioCodes 403 Forbidden: Microsoft Teams Direct Routing TLS connection rejected

SBC integration errorsMANUAL FIX INSIDEFREE — NO SIGNUP
Quick answer. Microsoft Teams Direct Routing validates the certificate chain your SBC presents against its trusted roots — currently Baltimore CyberTrust and DigiCert Global Root G2, with Microsoft actively migrating endpoints to the DigiCert root. If your AudioCodes firmware carries an outdated root store (or the TLS Context has no trusted root bound), the TLS handshake to sip.pstnhub.microsoft.com fails and Direct Routing rejects the connection with 403. The fix is to import the current Microsoft root certificates into the TLS Context trust store and restart the SIP TLS interface — not to touch your tenant or carrier configuration.

The raw code check

Run this before you change anything — it confirms the root cause in one pass:

openssl s_client — handshake from the SBCFAIL
$ openssl s_client -connect sip.pstnhub.microsoft.com:5061 -tls1_2
Certificate chain: sndc. ... (issuer: DigiCert Global Root G2)
verify error: unable to get local issuer certificate
403 Forbidden — TLS connection rejected by peer
openssl s_client — handshake after root importOK
$ openssl s_client -connect sip.pstnhub.microsoft.com:5061 -tls1_2
Certificate chain: sndc. ... (issuer: DigiCert Global Root G2)
Verify return code: 0 (ok) — chain to imported root
New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384

The manual fix — 3 steps

  1. Download the current Microsoft root certificates. Fetch the Baltimore CyberTrust root and the DigiCert Global Root G2 root from Microsoft's public PKI repository (microsoft.com/pki — the "PKI Repositories" page for Microsoft services). You need the roots Microsoft's Direct Routing endpoints chain to today, not the ones your firmware shipped with.
  2. Import the root into the AudioCodes TLS Context. Log into the AudioCodes Web GUI, open IP Network > Security > TLS Contexts, and import the root certificate into the trust store used by your Teams-facing TLS Context. Save the configuration. (Bulk-config shops: the same import is available via the ini parameter set for TLS.)
  3. Restart the SIP TLS connection and verify the handshake. Restart the SIP TLS interface (or reboot the TLS Context) so it reloads the trust store, then re-run the check above: openssl s_client -connect sip.pstnhub.microsoft.com:5061 -tls1_2 should return verify return code 0 and your Direct Routing session should re-register within a minute.

The automated alternative

If you'd rather never do this again: VoipFlow runs this whole class of maintenance as software — certificate issue-and-bind in about 12 seconds, signaling on port 5062 so SIP ALG rewriting never engages, per-tenant isolation, flat $399/mo. The 14-day sandbox is free, no credit card, and no sales follow-up unless you ask for one.

Deploy Free 14-Day Sandbox — No Credit Card Required

Related