Type something to search...
New root certificates required for Teams telephony

New root certificates required for Teams telephony


Introduction

If you have set up Teams telephony via Direct Routing in your Microsoft 365 environment, you depend on TLS/mTLS connectivity between Microsoft SIP proxies and your Session Border Controllers (SBC). Microsoft announced a significant change related to TLS certificates and certificate authorities (CAs), with a simple issue : if your SBC does not trust the new chain, you risk call failures and service disruption.

Microsoft recalls that TLS connectivity between its SIP proxies and SBCs relies on mutual TLS (mTLS), which involves client-side certificates with Client Authentication Extended Key Usage (EKU). However, since February 2025, Google (Chrome Root Program Policy v1.6) has changed its requirements and depreciates the use of Client Authentication EKU in server TLS certificates approved by Chrome. From June 2026, certificates must exclusively include Server Authentication EKU to maintain the trust of the main browsers (Chrome, Mozilla).


Supported certificate authorities (CAs)
CertificateThumbprint (SHA1)Serial number
DigiCert Global Root CAA8985D3A65E5E5C4B2D7D66D40C6DD2FB19C54360x083be056904246b1a1756ac95991c74a
DigiCert Global Root G2DF3C24F9BFD666761B268073FE06D1CC8D4F82A40x033af1e6a711a9a0bb2864b11d09fae5
DigiCert Global Root G37E04DE896A3E666D00E687D33FFAD93BE83D349E0x055556bcf25ea43535c3a40fd5ab4572
DigiCert TLS ECC P384 Root G517F3DE5E9F0F19E98EF61F32266E20C407AE30EE0x09e09365acf7d9c8b93e1c0b042a2ef3
DigiCert TLS RSA 4096 Root G5A78849DC5D7C758C8CDE399856B3AAD0B2A571350x08f9b478a8fa7eda6a333789de7ccf8a
Microsoft ECC Root Certificate Authority 2017999A64C37FF47D9FAB95F14769891460EEC4C3C50x66f23daf87de8bb14aea0c573101c2ec
Microsoft RSA Root Certificate Authority 201773A5E64A3BFF8316FF0EDCCC618A906E4EAE4D740x1ed397095fd8b4b347701eaabe7f45b3

What this means for you

The administrators of your SBCs will have to take the following points into account :

  • Ensure all certificate authorities are included in the SBC trust store.
  • Configure SBCs to trust client and server certificates.
  • Test that connectivity with Microsoft SIP proxies answers correctly.
  • Consult the SBC provider’s documentation for guidance on updating accepted certificate lists.

warning

SBCs without these new root CAs may experience certificate validation errors, impacting service availability.

Conclusion

These changes are not cosmetic, they affect the TLS trust base between Teams and your telephone infrastructure. The right reflex is to act as for any maintenance: update the roots, validate the chain, test the calls, and anticipate renewals, all before the end of February 2026 to avoid an interruption of service.


Sources

Microsoft Learn - New certificates required

Microsoft Learn - Azure certificate authority details

Message Center - MC1213773


Did you enjoy this post ? If you have any questions, comments or suggestions, please feel free to send me a message from the contact form.

Don’t forget to follow us and share this post.

Related Posts

How I resolved dropped Teams calls

How I resolved dropped Teams calls

Introduction A customer contacted me to tell me that he was having an issue with his Microsoft Teams telephony. Outgoing calls are being cut off even before the audio connection is establ

Read More
Pricing update for Teams telephony licenses

Pricing update for Teams telephony licenses

Introduction Microsoft recently announced a price increase for several Teams telephony licenses, effective April 1, 2025. This pricing update reflects the continued innovation and increased

Read More
The SMS messages will be native in Teams

The SMS messages will be native in Teams

Introduction Microsoft Teams continues to evolve, offering comprehensive communication and collaboration solutions. Among its features, SMS integration allows Teams users to easily communic

Read More
Import the DigiCert Root G2 certificate into a Ribbon SBC

Import the DigiCert Root G2 certificate into a Ribbon SBC

Introduction Since the arrival of Teams Direct Routing telephony, TLS certificates used by Microsoft servers are linked to the following root certification authority :Common Certificate

Read More
Import the DigiCert Root G2 certificate into an Audiocodes SBC

Import the DigiCert Root G2 certificate into an Audiocodes SBC

Introduction Since the arrival of Teams Direct Routing telephony, TLS certificates used by Microsoft servers are linked to the following root certification authority :Common Certificate

Read More
How to configure callback in a Teams queue

How to configure callback in a Teams queue

Introduction Callback in Teams allows callers in a queue to be called back after a certain time rather than waiting until an agent becomes available.Prerequisites **Required

Read More
How to handle duplicates in Teams directory search

How to handle duplicates in Teams directory search

Introduction Microsoft recently announced a significant optimization for the search by name and extension functionality in its Teams auto attendants. You have probably already had this case

Read More
How to inventory Direct Routing numbers in Teams

How to inventory Direct Routing numbers in Teams

Introduction Microsoft Teams continues to evolve to offer ever more effective communication and collaboration solutions. To make life easier for administrators, Microsoft has announced the

Read More
Debugging Teams calls via the SIP ladder

Debugging Teams calls via the SIP ladder

Introduction Microsoft Teams continues to evolve to offer ever more advanced communication and collaboration solutions. Among the features arriving very soon, we find the possibility of obt

Read More
How to analyze Direct Routing calls via the SIP ladder

How to analyze Direct Routing calls via the SIP ladder

Introduction I wrote an article last February to announce the upcoming release of the SIP ladder to analyze Teams Direct Routing calls from the Microsoft Teams Admin Center. The feature is

Read More
How to analyze incoming calls in Teams with CQD

How to analyze incoming calls in Teams with CQD

Introduction Microsoft's Teams Call Quality Dashboard (CQD) is a powerful tool designed to help administrators monitor and improve the quality of phone calls within their organization.

Read More
How to enable LDAP routing in an Audiocodes SBC

How to enable LDAP routing in an Audiocodes SBC

Introduction LDAP (Lightweight Directory Access Protocol) routing over an SBC (Session Border Controller) allows calls to be managed using information stored in an Active Directory.

Read More
Checking licenses for PSTN bot calls in Teams

Checking licenses for PSTN bot calls in Teams

Introduction Microsoft has announced an important update regarding license verification for PSTN bot calls to users in Microsoft Teams. This update aligns licensing requirements for Teams u

Read More
Managing call priorities in Teams call queues

Managing call priorities in Teams call queues

Introduction With the evolving use of Microsoft Teams as a business telephony solution, Microsoft is introducing a highly anticipated feature : call priority management in queues. This new

Read More
CyberGate connects your intercoms in Teams

CyberGate connects your intercoms in Teams

Introduction In a world where unified communications have become essential, CyberGate presents an innovative solution for integrating your IP devices directly into Microsoft Teams. Develo

Read More
How to configure a calling plan spend limit in Teams

How to configure a calling plan spend limit in Teams

Introduction Businesses interested in using Microsoft Teams as their single provider for telephony services, but reluctant due to the high cost of calling plans, can choose a *Pay-As-You-Go

Read More
How to configure and analyze emergency calls in Teams

How to configure and analyze emergency calls in Teams

Introduction Microsoft Teams telephony offers an essential feature for organizations : emergency call management. This feature allows users to make emergency calls while dynamically providi

Read More
How to use shifts in a Teams queue

How to use shifts in a Teams queue

Introduction The Shifts app in Microsoft Teams is a work schedule management tool designed primarily for frontline teams. It allows managers and employees to plan, view, share, and manage

Read More
How to reroute a 404 call with an Audiocodes SBC

How to reroute a 404 call with an Audiocodes SBC

Introduction When a call is sent to an unknown number or extension in a business telephony solution, the call fails and returns an error. Sometimes, this extension is known in another syste

Read More
How to validate the new Teams Direct Routing certificates

How to validate the new Teams Direct Routing certificates

Introduction In December 2025, Microsoft published a message MC1213773 in the Message Center of the Microsoft 365 Admin Center, explaining that new certificates were required to maint

Read More