The correct sequence is: assign Teams Phone licences, pick a PSTN connectivity option, get and assign numbers, set up emergency calling, then deploy devices with Intune and voice policies. Get roles and prerequisites right first, and each later step becomes routine rather than a fire drill.
TL;DR:
- Proper setup requires confirming tenant readiness, including billing access, roles, inventory, and network quality, to avoid costly rework and provisioning failures.
- Choosing the right PSTN connection depends on your organization's size, existing carrier contracts, and management capabilities, with Microsoft Calling Plan suited for smaller setups.
- Assigning phone numbers and resource accounts correctly, along with preparing auto attendants and call queues, is crucial for smooth call routing and capacity planning.
- Emergency location configuration varies by PSTN option and must be tested thoroughly to ensure accurate location reporting in emergencies.
- Enrolling Teams phones with Intune requires enabling Android Device Administrator and carefully configuring SignInMode policies to prevent setup issues and missing features.
Table of Contents
- Getting your tenant ready for a Teams phone setup
- Which licences and admin roles do you need?
- Which PSTN connectivity option should you choose?
- How do you get and assign phone numbers?
- How do you set up emergency calling?
- Setting up auto attendants and call queues
- Enrolling Teams phones with Intune
- Managing and monitoring your Teams phone deployment
- Deployment checklist: from planning to go-live
- How CTA Systems approaches Teams Phone rollouts
- Get help deploying Teams Phone properly
- Useful sources for your Teams Phone setup
Getting your tenant ready for a Teams phone setup
Provisioning fails most often because someone skipped groundwork, not because a step in the wizard went wrong. Before touching licences, confirm the basics.
- Confirm your Microsoft 365 tenant has billing access and an admin who can purchase licences.
- Assign least-privilege roles: use Teams Service or Teams Device admin roles for daily tasks, not Global Admin.
- Build an inventory: how many users need calling, how many shared devices, how many service numbers for queues or auto attendants.
- Check network readiness. Voice traffic needs sufficient bandwidth and Quality of Service (QoS) marking, particularly on sites with existing VoIP or heavy video conferencing load.
Skip the inventory step and you'll find yourself buying licences twice, once for the pilot and again when someone remembers the warehouse phone.
Which licences and admin roles do you need?
Two licence types matter here, and mixing them up causes real problems. A Teams Phone licence covers individual users who need a full calling experience. A Teams Shared Device licence covers common-area phones and meeting room handsets, with a reduced feature set that suits shared use rather than personal voicemail and call history.
Once the licence is assigned, voice-enable the account. You can do this manually in the Teams admin centre, or at scale using PowerShell with Set-CsPhoneNumberAssignment, which is faster once you're past a handful of users.
- Assign Teams Phone licences to individual desk and mobile users.
- Assign Teams Shared Device licences to reception phones, meeting rooms and common areas.
- Voice-enable accounts via the admin centre or PowerShell.
- Reserve Global Administrator for emergencies only; Teams Service or Device admin roles cover routine provisioning.
Pro Tip: Check licence compatibility before bulk-assigning. A Teams Rooms Basic licence applied to a standard Teams phone will block sign-in entirely, and you won't find out until the device is already on someone's desk.
Which PSTN connectivity option should you choose?
Microsoft offers four routes to the public phone network, and picking the wrong one early costs weeks later. The official breakdown covers three core models plus a mobile variant:
- Microsoft Calling Plan: fully cloud-managed, Microsoft handles the carrier relationship, fastest to deploy for smaller organisations.
- Operator Connect: your existing carrier connects directly into Teams without you managing session border controllers (SBCs).
- Direct Routing: you bring your own SBC, giving maximum control but requiring in-house telephony expertise.
- Teams Phone Mobile: SIM-based numbers that work as native mobile numbers inside Teams.
Choose based on international coverage needs, whether you already hold carrier contracts, and whether your team can manage an SBC. If you're unsure, check number availability and know-your-customer (KYC) requirements directly in the Teams admin centre before committing.
How do you get and assign phone numbers?
Number procurement depends entirely on which PSTN option you picked. Calling Plan numbers come straight from Microsoft; Operator Connect and Direct Routing numbers come through your carrier, then get attached to Teams. Follow this general sequence:
- Confirm number availability and porting timelines with your PSTN provider or Microsoft.
- Assign direct numbers to individual user accounts through the Teams admin centre or PowerShell.
- Assign service numbers to resource accounts used for auto attendants and call queues, since these need capacity for concurrent calls rather than a single-line number.
- Adopt a naming convention early (department, site, function) so a spreadsheet of fifty numbers doesn't become guesswork six months on.
Plan capacity for shared numbers before go-live. A toll-free line handling an auto attendant behaves nothing like a personal extension under load.
How do you set up emergency calling?
An emergency location tells the network where a call is physically coming from, which matters the moment someone dials emergency services from a Teams-enabled line rather than a traditional desk phone. Responsibility for this setup shifts depending on your PSTN choice: Calling Plan and some Operator Connect carriers handle parts of it automatically, while Direct Routing usually leaves you to configure locations manually.
- Define emergency locations by building, floor or site in the Teams admin centre.
- Assign each user or device to the correct location, especially on multi-site tenants.
- Test the emergency call flow before go-live and keep a written record of the test.
Pro Tip: Don't assume your carrier has this covered just because you're on Operator Connect. Ask them directly which parts of emergency location mapping they own, in writing, before your pilot goes live.
Setting up auto attendants and call queues
Resource accounts sit behind every auto attendant and call queue, and they need their own service number and licence before anyone can dial in. Build the greeting, the business hours menu, and the routing logic before you assign the number, not after.
- Create a resource account, assign a service number, then build the greeting and menu structure.
- Choose routing behaviour: serial, round robin or longest idle, depending on how your team wants calls distributed.
- Configure agent availability so calls don't ring through to someone who's stepped away.
- Set overflow and voicemail fallback so unanswered calls don't simply vanish; hold music settings live in the same configuration screen.
Test the full path yourself, dial in, sit through the menu, hang up on the queue, before you tell anyone the line is live.
Enrolling Teams phones with Intune
Teams desk phones run a stripped-down Android build with no Google Mobile Services layer, which means the normal Android enrolment flow doesn't apply. Devices must be enrolled using Android Device Administrator (ADA), and ADA enrolment is disabled by default on new tenants, so someone has to switch it on manually before the first handset can be added.
- Set Intune as your Mobile Device Management (MDM) authority before enrolling any device.
- Enable ADA enrolment in Intune if it hasn't been switched on already.
- Apply Conditional Access carefully: resource accounts can't complete interactive multi-factor authentication, so policies need to account for that.
- Control the on-screen experience with the IP phone policy SignInMode setting, using
UserSignIn,CommonAreaPhoneSignInorMeetingSignIndepending on the device's role.
A misconfigured SignInMode is the single most common reason a phone arrives at a desk missing its calendar or walkie-talkie app. Check it during rollout, not after the complaint ticket lands.
Managing and monitoring your Teams phone deployment
Configuring each handset by hand doesn't scale past a handful of devices. Configuration profiles in the Teams admin centre let you push a consistent setup, display settings, ringtones, sign-in behaviour, across a whole site in one pass instead of device by device.
- Build a configuration profile per device role (desk phone, common area, meeting room) rather than one blanket profile for everything.
- Watch call quality using Call Analytics for individual call troubleshooting and the Call Quality Dashboard for network-wide trends.
- Run a staged rollout: pilot with one team, expand to a floor, review call quality data, then roll out fully.
Pro Tip: Keep your pilot group small but genuinely diverse, include someone on a poor Wi-Fi connection and someone on a wired desk. That's where the real quality issues surface, not in the boardroom demo.
Deployment checklist: from planning to go-live
Work through this order and you won't discover a missing piece halfway through a rollout.
- Confirm prerequisites: tenant readiness, roles, inventory, network checks.
- Assign licences and voice-enable accounts.
- Choose and configure your PSTN connectivity option.
- Procure and assign phone numbers.
- Configure and test emergency calling.
- Build auto attendants and call queues.
- Enrol devices in Intune and apply SignInMode policies.
- Run a pilot, then expand and review before full rollout.
| Pilot acceptance item | What to check |
|---|---|
| Outbound and inbound calls | Clear audio, no dropped calls on wired and Wi-Fi connections |
| Emergency call flow | Correct location reported, test call logged |
| Number assignment | Correct caller ID displayed, no duplicate assignments |
| Device enrolment | Devices show correct SignInMode and app availability |
| Call quality monitoring | Call Quality Dashboard receiving data from pilot devices |
Most SME deployments move from prerequisites to a working pilot inside a few weeks, with full rollout depending largely on how many numbers need porting from an existing carrier.
How CTA Systems approaches Teams Phone rollouts
Every Teams Phone project we scope starts with the same question: what's the PSTN path, and who owns emergency calling once it's live? Getting that answer wrong costs more than any licence. We handle licensing, carrier liaison, Intune enrolment and the ongoing monitoring that keeps call quality from quietly degrading after go-live.
— Will
Get help deploying Teams Phone properly
Specialist providers can handle the parts that go wrong most often, including PSTN selection, number porting, Intune enrolment for shared devices, and the Conditional Access configuration that resource accounts genuinely need, to help prevent rollouts from stalling on technical issues.

If you're an SME weighing up Calling Plans against Direct Routing, or you've already got a pilot running and call quality is patchy on some sites, get in touch with CTA Systems for a discovery call. We'll look at your current setup, your carrier position, and your device estate, then tell you plainly what a properly supported rollout would involve.
Useful sources for your Teams Phone setup
Work through these alongside your own rollout plan rather than treating them as background reading.
- Set up Teams Phone in your organization for the full official roadmap.
- Deploy Teams Phones using Conditional Access and Intune for device enrolment and security policy detail.
