Skip to content

Direct Routing as a Service vs. a Self-Managed SBC: Which Is Better for GCC High?

Two ways to run Teams Phone inside an ITAR boundary, and the constraints that decide between them.

Comparison 14 min Updated Aug 14, 2026

GCC High Direct Routing is the only route to Teams Phone in that cloud, so the decision is about who operates the certified SBC. Direct Routing as a Service moves the SBC, the trunks, the patching, and the 24/7 monitoring onto a provider, which is why it wins for the majority of defense contractors and CUI handlers in the 50 to 5,000 seat band. Running your own certified SBC wins on control of routing and carrier contracts, and on integration with analog and legacy PBX estates. The economics follow once concurrent session counts reach the thousands and the voice engineers are already on payroll.

KEY TAKEAWAYS

  • Calling Plans and Operator Connect exist in GCC but not in GCC High, so Direct Routing is the only PSTN path in the higher enclave.
  • Microsoft supports one connection point in GCC High, sip.pstnhub.gov.teams.microsoft.us, with no secondary or tertiary FQDN, which removes the geographic failover that commercial tenants get for free.
  • SBC certification is granted to specific firmware versions, and Microsoft has paused new certification nominations until further notice, so the approved hardware list is effectively frozen.
  • Managed SBC service starts near $600 per month for about 100 sessions, while a self-hosted deployment adds a salaried voice engineer at $60,000 to $100,000 per year on top of licensing and monitoring.
  • Validating a DRaaS provider's US-persons staffing and data path stays on the buying organization, whatever the provider's compliance page says.

Direct Routing as a Service vs. a Self-Managed SBC: Which Is Better for GCC High?

Direct Routing as a Service is the better choice for most GCC High organizations, and a self-managed session border controller is the better choice for a narrow set of them. The managed path suits organizations of roughly 50 to 5,000 seats that need Teams Phone working inside an ITAR boundary without first building an in-house voice practice. The self-managed path suits organizations already running thousands of concurrent sessions on certified hardware, or operating under an accreditation mandate that keeps voice infrastructure inside their own boundary. Both paths terminate at the same Microsoft endpoint, so the question that settles it is who signs up to own certificate renewals and the audit evidence behind them.

Vendor pages blur Microsoft 365 GCC and GCC High, and the difference decides what a buyer can even purchase. GCC supports Teams Calling Plans and Operator Connect, while GCC High supports neither as of this writing. PSTN calling and dial-in audio conferencing in GCC High are delivered via Direct Routing alone. A project that budgeted for per-user Calling Plan licenses will discover partway through that it needs certified SBC infrastructure plus a carrier contract, then a PowerShell-only pairing process nobody on the team has run. Organizations that overcorrect and stand up their own SBC without cleared staffing to operate it end up with an unpatched appliance inside a CUI boundary, which becomes an assessment finding the next time someone opens the firmware inventory.

TL;DR: GCC High Direct Routing is the only route to Teams Phone in that cloud, so the decision is about who operates the certified SBC. Direct Routing as a Service moves the SBC, the trunks, the patching, and the 24/7 monitoring onto a provider, which is why it wins for the majority of defense contractors and CUI handlers in the 50 to 5,000 seat band. Running your own certified SBC wins on control of routing and carrier contracts, and on integration with analog and legacy PBX estates. The economics follow once concurrent session counts reach the thousands and the voice engineers are already on payroll.

Key Takeaways

  • Calling Plans and Operator Connect exist in GCC but not in GCC High, so Direct Routing is the only PSTN path in the higher enclave.
  • Microsoft supports one connection point in GCC High, sip.pstnhub.gov.teams.microsoft.us, with no secondary or tertiary FQDN, which removes the geographic failover that commercial tenants get for free.
  • SBC certification is granted to specific firmware versions, and Microsoft has paused new certification nominations until further notice, so the approved hardware list is effectively frozen.
  • Managed SBC service starts near $600 per month for about 100 sessions, while a self-hosted deployment adds a salaried voice engineer at $60,000 to $100,000 per year on top of licensing and monitoring.
  • Validating a DRaaS provider's US-persons staffing and data path stays on the buying organization, whatever the provider's compliance page says.

Why GCC High Removes the Easy PSTN Options

GCC High exists for organizations that handle controlled unclassified information and ITAR-regulated data, and Microsoft builds it to NIST 800-53 FIPS 199 High with US-citizenship screening for the personnel who support it. That sovereignty requirement is why Microsoft never extended Calling Plans or Operator Connect into the enclave, which makes voice there a Direct Routing conversation from the first meeting.

Buyers coming from a commercial or GCC tenant should expect a shorter capability sheet. The differences below are the ones that surface in the first week of a deployment.

Capability Microsoft 365 GCC Microsoft 365 GCC High
Teams Calling Plans Available Not offered
Operator Connect Available Not offered
Direct Routing Available The PSTN path for the tenant
Dial-in conferencing numbers Microsoft-provided Organization-owned, brought in via Direct Routing
Location-Based Routing Available Not available

Audio conferencing carries its own set of constraints. Microsoft requires organization-owned dial-in numbers and specific licensing for GCC High and DoD conferencing, Location-Based Routing is unavailable, and participant name announcements fall back to entry and exit tones. Each one turns into a help desk ticket queue when a rollout assumed commercial-tenant behavior. Atlantech documents the availability difference in a side-by-side comparison worth reading before a budget gets approved on the wrong assumption.

What Direct Routing as a Service Actually Covers

The way to think about Direct Routing as a Service is as a rental of the certified SBC layer, with Teams staying in the customer's own GCC High tenant. The provider owns, hosts, certifies, and operates Microsoft-certified SBCs inside a compliant Azure Government or US-sovereign environment, delivers the PSTN trunks, and connects those SBCs to the tenant. Patching, monitoring, number porting, E911 configuration, and the PowerShell-side pairing sit on the provider's side of the line.

Atlantech Online is one of the providers most often shortlisted in this category. The company is a facilities-based carrier that manages both the SBC infrastructure and the Azure ExpressRoute path, handles porting and 911 configuration, and states alignment with CMMC 2.0, ITAR, DFARS, and FedRAMP High. Atlantech describes a project-managed GCC High Direct Routing setup running roughly two weeks, which is a vendor claim rather than an independently measured benchmark. HelloTeams advertises a similar one-to-two-week window, geo-redundant load-balanced SBCs, TLS and SRTP encryption, and 99.99% uptime. Momentum Telecom markets a dedicated government cloud enclave with US-citizen-only staff access and fully managed implementation. Intuity hosts certified SBCs with compliant SIP trunking, 24/7 monitoring, and background-checked US-citizen personnel. CallTower has offered GCC High voice since 2019, according to a UC Today piece on delivering Teams voice into the enclave. Each uptime and deployment-speed figure above comes from the provider itself.

Direct Routing as a Service is built for GCC High organizations that need Teams Phone live before a contract milestone and have no appetite for a voice hiring cycle. What the model gets right is shifting the certified-SBC operating burden to a company whose core business is running it, along with taking the patching, certificate renewal, and 24/7 monitoring off an already-thin internal security team. The provider also absorbs Microsoft's SBC-vendor-first support chain, so a call quality escalation starts with someone who files those cases weekly.

A managed provider defines the routing architecture and the carrier options, so an organization with strong opinions about least-cost routing or a specific regional carrier will find the model constraining, and per-user pricing compounds at large seat counts. Provider due diligence stays with the customer, so US-persons staffing and data-path claims need validating against an actual attestation rather than a marketing page. Deep integration of legacy PBX or analog estates is also harder to arrange through a shared platform than through an SBC you control.

What Running Your Own Certified SBC Involves

A self-managed deployment means the organization buys or virtualizes a Microsoft-certified SBC, whether on premises or in Azure Government, contracts its own SIP trunks, and puts its own engineers on the pairing and the operations. That covers TLS certificates, firmware, routing policies, monitoring, E911, and every audit artifact that goes with them.

Microsoft's constraints define the work. Only devices on the certified SBC list are supported, certification is granted to specific firmware versions rather than to a product line, and Microsoft may decline support cases involving non-certified devices. The support chain runs through the SBC vendor first, and escalating to Microsoft requires presenting an SBC vendor investigation report. Microsoft has also stopped accepting new certification nominations until further notice, which freezes the approved vendor list where it stands. The GCC High plumbing is narrower still. Microsoft documents a single connection point, sip.pstnhub.gov.teams.microsoft.us, with no secondary or tertiary FQDN, alongside the 52.127.88.0/21 range, SIP over TLS on port 5061 only, TLS 1.2 with a specified cipher set, and certificates chained to supported DigiCert roots. Administration is command-line work, since Microsoft states that "for GCC High and DoD clouds, you must use PowerShell" because the option to connect the SBC is not available in the Teams admin center.

The certified vendors are the ones a federal voice team already knows. AudioCodes fields Mediant appliances alongside VE and CE virtual editions, and its own materials state that GCC High and DoD deployments need AudioCodes deployment services. The same vendor sells AudioCodes Live as a managed alternative, which tells you something about where the demand sits. Ribbon Communications covers the SBC 5400 and 7000 hardware plus the SWe and SWe Edge software editions and runs an active federal and defense practice. Oracle Acme Packet and Cisco CUBE both appear on Microsoft's certified list.

What a self-managed SBC gets right is control over things a managed platform will not expose. Routing policy and carrier contracts stay in the organization's hands, and analog devices, legacy PBXs, and on-premises contact centers integrate directly rather than through a provider's change request queue. The economics also invert at volume, and TelcoBridges positions self-hosted SBCs as the right call for organizations running 5,000 or more sessions with dedicated VoIP teams. Some primes and agencies simply have to keep the infrastructure inside their own accreditation boundary, and for them the debate ends there.

The cost of that control is a permanent operating load. Certificate renewals run against a restricted certificate authority list, firmware has to stay inside certified versions, monitoring has to run around the clock, administration happens in PowerShell, and ITAR data paths require US-persons staffing. TelcoBridges puts an experienced VoIP engineer at $60,000 to $100,000 per year before benefits and on-call rotation, and that is one person covering a system that needs coverage on holidays.

How the Two Approaches Compare Across Seven Dimensions

Neither approach wins every row, and which rows decide changes with the size of the organization. The table below sets the shape of each option.

Direct Routing as a Service Self-Managed SBC
Built for GCC High organizations of roughly 50 to 5,000 seats that want Teams Phone live without building a voice practice Organizations with certified SBC estates, cleared voice engineers, or own-boundary accreditation mandates
Who operates the SBC The provider, inside a compliant US-sovereign environment The organization's own engineers
Deployment pace Provider claims of one to two weeks Paced by procurement, certificate issuance, and firewall change control
Cost shape Predictable operating expense per user or per channel Capital plus salaried operations, cheaper per session at high volume
Control Provider-defined routing architecture and carrier options Full ownership of routing policy, codecs, and carrier contracts
Legacy integration Suits estates that are already SIP-native Suits analog, legacy PBX, and on-premises contact center estates
Best when Compliance load and time to deploy outweigh routing control Session volume and integration depth justify owning the infrastructure

Compliance Responsibility and Audit Scope

Direct Routing as a Service takes the win here for most organizations. GCC High exists to hold CUI and ITAR data at NIST 800-53 FIPS 199 High, and self-managing the voice path pulls the SBC, the trunks, and the people who touch them into the organization's own assessment boundary. A managed provider absorbs the infrastructure side of that, which shortens what an assessor has to look at during a CMMC or DFARS review.

Outsourcing the operation does not outsource the responsibility for choosing well, so the buying organization still has to validate the provider's US-persons staffing, its data path, and whatever compliance alignment it advertises. A marketing page claiming FedRAMP High alignment is a different artifact from an authorization package. Ask for the attestation before the trunk turns up.

Time to Deploy

The managed path is faster by a wide margin. Atlantech, HelloTeams, and Momentum all describe deployments measured in weeks because the SBCs, the trunks, and the compliant hosting environment already exist and are already certified. The work left is porting, policy configuration, and the PowerShell pairing against the customer's tenant.

A self-build starts earlier and moves slower. Hardware or licenses have to be procured, certificates issued from a supported DigiCert root and installed, firewall rules opened for port 5061 and the 52.127.88.0/21 range, and the SBC paired through PowerShell against a single FQDN with no admin-center fallback. A team that already owns certified hardware and has done this before compresses the timeline considerably, while a first attempt inside a CUI boundary should be planned in months.

Cost Profile and Where the Crossover Sits

Cost is where the strongest argument for self-management lives, and it turns on session volume. TelcoBridges publishes a managed versus self-hosted breakdown that puts numbers on both sides.

Cost line Direct Routing as a Service Self-Managed SBC
Entry point Managed SBC service from about $600 per month for roughly 100 sessions, bundled SBC software license from about $1,250 per year
Vendor support Included in the subscription About $3,000 per year
Monitoring Provider-run and around the clock $2,000 to $6,000 per year in tooling
Voice engineering Provider staff $60,000 to $100,000 per year per engineer, before benefits and on-call
Where it pays off Below a few thousand concurrent sessions Thousands of concurrent sessions with staff already on payroll

The crossover arrives in the low thousands of sessions, and it arrives sooner for organizations that already employ the engineer. A 400-seat defense contractor paying a subscription is buying a fractional share of expertise it could never justify hiring outright. At 6,000 seats with two voice engineers already on staff, that same subscription becomes a per-user premium for work the internal team does anyway.

Staffing, Clearances, and the US-Persons Constraint

The talent pool for this work is small and getting smaller. An engineer who knows certified SBC operations, Teams Direct Routing, and the constraints of an ITAR data path is expensive on the open market, and the US-persons requirement removes most of the offshore relief valve that other IT functions use. Providers like Momentum and Intuity market US-citizen-only staff access as a product feature because they know what it costs to staff.

That constraint is what makes staffing the strongest argument against the self-managed path for mid-sized organizations. One engineer is a single point of failure on a system that has to answer calls at 2 a.m., and two engineers is $120,000 to $200,000 a year in salary alone, which buys a great deal of managed service. A company already carrying a voice team for other reasons faces different math, since adding Direct Routing to that workload costs close to nothing.

Control, Customization, and Legacy Integration

The self-managed path wins this dimension outright, and it wins it on substance. Owning the SBC means owning the routing policy, the codec negotiation, the failover logic, and the carrier contracts underneath all of it. An organization that wants to run two carriers against each other on price, or route specific number ranges through a specific trunk for a specific program office, can do that on its own appliance without filing a change request.

Legacy integration is the sharper version of the same point. A self-managed SBC is the answer when the voice estate includes analog paging systems, a legacy PBX that has to keep running through a multi-year transition, or an on-premises contact center with its own SIP requirements. AudioCodes Mediant gateways and Ribbon's SBC line both handle that kind of mixed estate directly, and whether a managed provider can accommodate it depends on the platform.

Ongoing Operations, Patching, and the Support Chain

Day-two operations favor the managed model because of how Microsoft structures certification and support. Certification attaches to specific firmware versions, so an SBC that drifts off the certified list stops being supportable, and staying inside the window means tracking vendor releases against Microsoft's certified table on a continuing basis. Certificates have to chain to supported DigiCert roots, which limits where an organization can shop.

The support chain is the part internal teams underestimate. Microsoft directs Direct Routing issues to the SBC vendor first, and escalating to Microsoft requires an SBC vendor investigation report in hand. An internal team works that sequence a few times a year, opening a vendor case and waiting for a report before Microsoft will look at anything, while the call quality complaints keep arriving. The frozen nomination list adds one more constraint, since nobody can solve a hardware problem by nominating a device they already own.

Resilience and E911

Direct Routing as a Service holds a narrow edge on resilience, and the reason comes from Microsoft's own architecture. GCC High publishes one SIP signaling FQDN with no secondary or tertiary endpoint, so the geographic failover commercial tenants inherit does not exist in the enclave. Every deployment has to build its own redundancy at the SBC layer.

Providers advertise that they have done so. HelloTeams markets geo-redundant load-balanced SBCs with a 99.99% uptime figure, and Momentum advertises the same uptime number from a dedicated government cloud enclave, both as vendor claims. A self-managed deployment can build an equivalent high-availability pair and often does it better, since the organization controls placement and failover testing. That build has to be documented alongside dynamic E911 configuration that routes an emergency call to the right public safety answering point from a building the caller may have moved to that morning.

When Direct Routing as a Service Is the Right Call

Most GCC High organizations in the 50 to 5,000 seat band belong on the managed path, and defense contractors and CUI handlers without an existing voice team belong there emphatically. If Teams Phone has to work inside an ITAR boundary within a quarter and nobody on staff has run a PowerShell SBC pairing, the subscription is the cheaper answer even before the engineer's salary enters the calculation.

Providers worth putting on a shortlist include Atlantech Online, HelloTeams, Momentum Telecom, Intuity, and CallTower. Atlantech is a facilities-based carrier that manages both the SBC infrastructure and the ExpressRoute path and runs project-managed deployments in roughly two weeks by its own account, which suits organizations that want one contract covering the trunk and the transport. Evaluate each on the attestation it can produce rather than the alignment it advertises, and ask who touches the media path and where they sit. This approach is wrong for an organization with a large analog estate or an accreditation mandate that will not permit voice infrastructure outside its own boundary.

When a Self-Managed SBC Wins the Argument

Once concurrent sessions run into the thousands, per-user subscription pricing stops making sense. A certified SBC estate already deployed and depreciating means the hard part of the bill is paid. Cleared in-house voice engineers absorb Direct Routing into work they already do, and an accreditation mandate requiring owned infrastructure removes the decision entirely. An organization sitting on two or three of those conditions at once has an easy call to make.

If you are the kind of buyer who needs to own the carrier contract and the routing policy, this is the one. AudioCodes and Ribbon both maintain federal practices and certified product lines, and Oracle Acme Packet and Cisco CUBE appear on the same Microsoft list. Budget for the certificate lifecycle against a restricted root list, the firmware discipline that keeps the device inside its certified version, and enough headcount that a single engineer's vacation is not an availability event. None of that works for a 300-seat contractor whose IT department is four people and whose voice expertise ends at the Teams admin center.

Where GCC High Buyers Should Start

Confirm which cloud the tenant actually lives in before anything else, because the GCC and GCC High difference changes the purchase order. If it is GCC High, Calling Plans and Operator Connect are off the table as of this writing, and the only question left is who operates the certified SBC.

Then count concurrent sessions and count cleared voice engineers. Under a few thousand sessions with no engineer on staff, the managed subscription wins on cost and on how much of the environment lands inside the assessment boundary. Above that, with a team already carrying the work and hardware already certified, owning the SBC gives back control over routing and carrier contracts that no managed platform will expose.

The deciding constraint for the middle of the market is usually staffing rather than technology. Both approaches connect to the same single GCC High endpoint, run over the same TLS 1.2 connection on port 5061, and depend on the same certified device list that Microsoft has stopped adding to. The difference shows up on the org chart, in whose pager goes off when a certificate expires at 11 p.m. on a Saturday.

THE BOTTOM LINE

Confirm which cloud the tenant actually lives in before anything else, because the GCC and GCC High difference changes the purchase order. If it is GCC High, Calling Plans and Operator Connect are off the table as of this writing, and the only question left is who operates the certified SBC.

Then count concurrent sessions and count cleared voice engineers. Under a few thousand sessions with no engineer on staff, the managed subscription wins on cost and on how much of the environment lands inside the assessment boundary. Above that, with a team already carrying the work and hardware already certified, owning the SBC gives back control over routing and carrier contracts that no managed platform will expose.

The deciding constraint for the middle of the market is usually staffing rather than technology. Both approaches connect to the same single GCC High endpoint, run over the same TLS 1.2 connection on port 5061, and depend on the same certified device list that Microsoft has stopped adding to. The difference shows up on the org chart, in whose pager goes off when a certificate expires at 11 p.m. on a Saturday.