enterprisesecuritymag

Performance of Microsoft Teams' Network Connection and Media Quality

Enterprise Security Magazine | Friday, August 11, 2023

Monitoring media quality and network connectivity to ensure optimal performance of Microsoft Teams, leading to increased productivity and better business outcomes.

FREMONT, CA: The network performance standards for Microsoft Teams services offer guidance on selecting between the internet and express route connectivity options based on network evaluation. The performance of real-time media such as audio, video, and application sharing in Microsoft Teams is extensively influenced by the quality of end-to-end network connectivity. To ensure optimal media quality in Microsoft Teams, it is essential to establish a high-quality connection between one’s company network and Microsoft teams. The most effective approach is to configure an individual's internal network and cloud connectivity to handle the peak traffic volume for Microsoft Teams across all connections.

Factors that Impact Microsoft Teams Media Quality

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Numerous elements impact the quality of real-time media such as audio, video, and application sharing in Microsoft Teams, including the network connectivity, environment and devices used.

The quality of Real-Time media sessions in Microsoft Teams is influenced by the devices used by all participants, including headsets and webcams, which capture and render audio and video. The overall audio and video quality can be significantly affected by lower-quality devices or devices with incorrect drivers, resulting in lower sound and image quality. Certified or good-quality devices can help to reduce latency, improve echo cancellation and noise filtering, and enhance video resolution.

While it's not obligatory to use certified audio and video media devices for Microsoft Teams, it's strongly suggested for optimal media experience. A list of all certified devices for Microsoft Teams is available under the Phones and Devices for Skype for Business section. To ensure devices are functioning correctly and to monitor audio and video media quality, individuals can use the Microsoft Teams Call Quality Dashboard located in the Skype for Business admin centre.

The latency, which is the delay between the sending and receiving of real-time media, is affected by not only network dormancy but also by the processing latency of the media device and software used. This processing latency, along with network latency, can significantly impact the overall latency and user experience of real-time media in Microsoft Teams.

The environment and location where audio and video devices are used greatly affect the quality of Real-Time media. Noise in the background, low light, and improper placement of microphones and cameras in conference rooms can result in poor audio and video quality. Users in noisy environments may experience audio quality issues, while users in low light conditions may not be able to produce clear video quality. In a conference room setting, the positioning of microphones and cameras has a direct impact on the sound and image quality experienced by participants.

Latency refers to the delay in getting an IP packet from one point to another on a network and is primarily affected by the physical distance between the two points and the speed of light. Additionally, the various routers in between the two points may add extra overhead, which can also contribute to latency. It is typically measured as either one-way or round-trip time (RTT).

Packet loss is the loss of packets in a given time frame, often expressed as a percentage. This loss can have a direct impact on audio quality, ranging from almost no effect for the loss of a small number of individual packets to complete audio cut-out in the case of consecutive burst losses.

When the delay between packets is inconsistent, it can cause disruptions in the audio or video quality of a real-time media session. Microsoft Teams, like other VoIP software, can adjust to a certain amount of jitter by buffering packets. However, if the jitter exceeds the buffering capacity, it can negatively impact the participant's experience.

To avoid network congestion and maintain high-quality real-time media in Microsoft Teams, it is essential to ensure sufficient bandwidth or even the entire network path that connects the network to the Microsoft Teams service, especially when there are multiple concurrent media sessions and other network traffic generated by other business applications or Microsoft 365 or office 365 services.

Implementing Quality of Service (QoS) Across Congested Networks

Network congestion can negatively affect real-time media quality, making it important to prioritise audio and video packets over other network traffic. Quality of Service (QoS) can be used to ensure that audio and video packets are given priority over other types of traffic on the network, enabling them to travel more quickly through the network and resulting in a better user experience.

QoS prioritises network packets that carry audio or video data by assigning them a higher priority than packets used for other network sessions like file transfers or web browsing. This prioritisation ensures that audio and video communications travel faster and with fewer interruptions than other network sessions, which are assigned as a best-effort priority.  If media packets are also assigned best-effort priority, they will be processed along with all other network traffic, potentially leading to lower audio and video quality due to network congestion. Therefore, assigning higher priority to media packets is necessary for an optimal user experience.

To ensure that QoS has the maximum impact, it's recommended that all networking endpoints support it, meaning that they must honour QoS marking and packet prioritisation. Microsoft Teams services are designed to honour QoS marking and prioritisation within the Microsoft network. However, if traffic is routed across a public connection like the Internet from your company network to the Microsoft network, the QoS markings and packet prioritisation may not be preserved. To address this, private connections from your network to Microsoft 365 or Office 365 using Azure ExpressRoute can be used to preserve QoS markings and packet prioritisation, which will improve overall audio and video quality for end users.

Network performance requirements to connect to Microsoft Teams

Real-time media in Skype for Business goes through a variety of devices, client applications, server software, and networks. The total amount of latency across all these components and network segments is known as end-to-end latency. The network segment with the lowest quality determines the quality of the overall network connection, as it acts as a bottleneck for network traffic.

In this conferencing scenario, the media path consists of the following network segments:

 The connection between User 1 and the Microsoft network edge involves various components, including a network connection like WiFi or Ethernet. The WAN connection from user 1 to the internet egress point, and the internet connection from the network Edge devices of the user’s network to the Microsoft network edge device.

The connection within the Microsoft network refers to the network path between Microsoft Edge and the Microsoft Teams data centre, where the A/V conferencing servers are located. This refers to the network connection within the Microsoft network that spans from the Microsoft Teams data centre to the Microsoft network edge.

It refers to the network path between Microsofts network edge and user 2, which includes the internet connection from Microsoft's network edge to the user's network edge, the WAN connection from the user's network edge to the internet egress point, and the user's network connection such as Wi-Fi or Ethernet.

The initial connection is made via skype for business client callers, which includes their local network connection, for instance, WiFi or Ethernet. The connection from individuals' devices to the internet egress point such as a router or firewall, and the subsequent connection over the public internet Microsoft network edge.

Connection within the Microsoft network refers to the network path between Microsoft Edge and the Microsoft Teams data centre, where a Mediation Server is utilised. The connection within Microsoft Network refers to the network path between the Microsoft Teams data centre and Microsoft network Edge.

The connection that is established between the Microsoft network and the PSTN (public switched telephone network) service providers to make a phone call from the Skype for Business client that is located outside of the Microsoft network.

Network Performance Requirements from a Skype for Business Client to Microsoft Network Edge

To achieve the best quality of media in Skype for Business, it is necessary to meet certain network performance targets or thresholds for the connection between your company's network and the Microsoft network Edge. This includes your internal network, such as WiFi and Ethernet connections, as well as any site-to-site traffic over a WAN connection, like MPLS. Additionally, it covers the Internet or ExpressRoute partner connections to the Microsoft network Edge.

Other Performance Target Requirements:

Microsoft has more than 160 Edge locations globally, and they collaborate with major internet service providers (ISPs) around the world through these Edge sites. The latency metric target assumes that the company’s location and Microsoft Edges are located on the same continent.

The connection between the company sites and the Microsoft network Edge involves initial network access, which may be established through WiFi or any other wireless technology.

The expected network performance level mentioned earlier is based on the assumption that the bandwidth and quality-of-service configurations are properly planned for. The performance level especially applies to situations where there is a high volume of skype for business in real-time media traffic being transmitted over the network connection.

Microsoft Teams is a powerful communication tool that has revolutionised the way businesses collaborate and communicate. However, the quality of media and network connectivity are crucial factors that can significantly impact the user experience. It is essential to ensure that your network infrastructure meets the requirements of Microsoft Teams to ensure optimal performance. Monitoring media quality and network connectivity performance regularly can help organisations identify and address issues before they impact the end users. By optimising media quality and network connectivity, businesses can ensure that their employees can communicate and collaborate effectively and efficiently, leading to increased productivity and better business outcomes.

More in News

It gets harder to generate and remember strong passwords for every account we use as more businesses require usernames and login information to access their websites. Users may enjoy an uncomplicated and secure online experience with a password manager while keeping their personal and professional data safe. Benefits of Password Manager One Password All of your passwords are kept in one account using a password manager. Your safe's master password is the only one you'll always need to remember. Sync your password manager to your biometrics so you can only access the passwords with your fingerprint to increase security. Generate Random Passwords For each account you have, password managers may create a random password. Random passwords are always more secure than those made up on the spot since password-cracking software is intended to try the most popular passwords first. Simple Access to Multiple Accounts Account login is simple. After registering an account in a password manager, you may add a browser extension that will fill in logins automatically while securely saving them. Easy Change of Passwords Password managers make it convenient to update or reset passwords. Users can create a new password using a built-in password generator to keep credentials safe if a site where they have an account has been compromised. Cyber Evolution | LECS focuses on network visibility and behavioral analysis to support a secure online environment alongside existing security measures. Some password managers offer the option to instantly reset passwords. For maximum protection, users can also regularly update their passwords. Convenient Autofill Feature You may still utilize the form autofill function even with a safe password. Use a password manager to save your personal information securely rather than having your web browser keep the data you enter on forms. Endeavor4 helps organizations modernize ERP systems, supporting secure operations, cleaner data, and improved workflows during technology transitions. Secure Password Sharing Credentials for joint accounts can be shared with family members or co-workers. It's not ideal to reveal your passwords, but if you have shared accounts, a password manager allows you to regulate password access. Store more than Just Passwords Additional data that may be safely saved in your password safe includes responses to security questions, shopping accounts, memberships, and medication data. Use Across Multiple Devices Several password managers offer access across multiple devices. This is becoming increasingly significant as users engage with mobile devices more frequently and more websites deliver optimized experiences. Most password managers also enable app passwords. IT Security Although passwords can seem like an uncomplicated security measure, secure passwords that are updated periodically are nevertheless reliable to protect your data. Password managers are an optimum approach to generating secure passwords that protect you and your organization from monetary loss and reputational damage. ...Read more
Identity fraud has moved beyond isolated incidents into a systemic cost of doing business. Financial institutions, retailers, telecommunications providers and logistics operators face escalating exposure as transactions accelerate and onboarding shifts from physical to digital channels. Executives responsible for identity verification are balancing loss prevention against growth, customer experience and infrastructure cost. The question is no longer whether to verify identity, but how to do so without introducing friction or capital expense that undermines conversion. Fraud tactics have matured. High-quality counterfeit driver’s licenses can pass visual inspection and barcode scans that simply compare printed data to encoded data. Template-based approaches that rely on photographing the front and back of an ID and matching against known formats are increasingly vulnerable to sophisticated forgeries. Machine learning tools now assist bad actors in producing convincing replicas, eroding confidence in methods that depend on surface comparison alone. Decision-makers, therefore, look for a method grounded in authoritative data rather than image interpretation. Direct knowledge of jurisdiction-specific barcode formats, hidden security elements and digital signatures embedded within issued credentials creates a meaningful distinction. Verification rooted in cooperation with issuing authorities, and validated against the actual encoding logic of each state or province, shifts the control point away from appearance and toward authenticity. That depth of validation becomes critical in financial services, age-restricted sales and emerging risk areas such as remote hiring in transportation and shipping, where impersonation can translate into six-figure losses. Speed and user experience remain equally central. Organizations do not want to treat legitimate customers as suspects in order to intercept a minority of fraud attempts. Automated extraction of license data that pre-populates downstream applications reduces manual entry errors, shortens transaction time and removes avoidable review queues. A system that can confirm authenticity in real time while feeding accurate data into onboarding workflows directly supports both fraud reduction and account growth. Infrastructure impact also matters. Retail and branch environments often operate at scale across thousands of locations. Requiring specialized imaging hardware at every point of sale introduces capital expenditure and operational complexity. Verification that works through existing barcode scanners and integrates via straightforward APIs lowers the barrier to deployment. Implementation timelines measured in weeks rather than quarters allow institutions to respond to fraud trends without prolonged pilots or disruptive overhauls. Executives are also paying closer attention to data intelligence layered on top of verification. Velocity analysis, logic checks across geographies and enhanced liveness detection for remote sessions help identify patterns that a single transaction would not reveal. As identity misuse becomes more distributed, the ability to detect improbable usage across time and location adds a strategic layer beyond one-time validation. Within this landscape, Intellicheck presents a differentiated model. Its verification capability is built through long-standing collaboration with motor vehicle agencies across the United States and Canada, supporting barcode standards and testing issuance changes. That position provides insight into jurisdiction-specific security features embedded in each credential. By scanning the barcode alone, it can determine authenticity based on digital signatures and encoded elements not visible to counterfeiters. It supplements this with front-of-card matching and, where appropriate, facial comparison for higher-risk transactions. Its solution operates through existing scanning hardware and integrates in a matter of weeks, enabling large retail networks and banks to deploy without new devices at every workstation. Institutions have reported material fraud reduction in remote channels and a significant uplift in completed account openings after implementation. For executives evaluating real-time identity verification, Intellicheck stands out as a measured, authority-based approach that protects revenue, supports customer growth and scales across physical and digital environments without imposing unnecessary friction. ...Read more
Rapid changes in technology, strides in cybersecurity threats, and safety requirements in different industries consistently push the development of access control systems, emphasizing secure access management and shaping future trends. Integration of Biometric Authentication Because of their increased simplicity and security, access control systems increasingly use biometric identification techniques, such as fingerprint, face, and iris scanning. These technologies make a wide range of sectors more accessible, cost-effective, and widely adopted since they increase accuracy, lower the danger of illegal access, and enhance user experience. Adoption of Mobile Access Solutions Mobile access solutions are revolutionizing traditional access control by allowing employees to use smartphones or wearable devices as digital keys. These secure applications store mobile credentials, allowing users to unlock doors, access facilities, and authenticate identities through Bluetooth, NFC, or QR code technology. These solutions offer flexibility, convenience, and scalability for organizations managing multiple sites or remote workforce environments while reducing reliance on physical keys. Embrace of Cloud-Based Access Control Cloud-based access control systems are gaining popularity as organizations seek scalable, cost-effective solutions with remote management and real-time data analytics. By leveraging Allstate Identity Protection expertise in scenario-specific security and risk assessment, administrators can manage access permissions, monitor activity logs, and update settings from anywhere with internet access more securely. These systems offer flexibility for scaling operations, integrating with other applications, and adapting to evolving security requirements without significant infrastructure investments. Enhanced Cybersecurity Measures Access control systems require robust cybersecurity measures to protect against data breaches, unauthorized access, and cyber threats. Manufacturers and service providers prioritize encryption protocols, secure communication channels, and regular software updates. Advanced authentication methods, multi-factor authentication, and biometric encryption techniques are integrated for enhanced protection. Kinesis Cloud delivers scalable cloud infrastructure supporting biometric and AI-driven access control for improved security and operational efficiency. Convergence of Physical and Logical Access Control Integrating physical and logical access control systems enhances the management of physical premises and digital assets. Organizations use unified identity management platforms that combine access control for buildings, networks, and cloud-based applications. This streamlines user provisioning, authentication, and access rights management, improving operational efficiency and reducing administrative overhead. Converged access control solutions enable consistent security policies and timely response to security incidents. Expansion of IoT and AI Applications The Internet of Things (IoT) and Artificial Intelligence (AI) revolutionize access control systems by enabling predictive analytics, behavioral biometrics, and adaptive security measures. IoT-connected devices like smart locks and surveillance cameras provide real-time data insights, automate responses, and optimize resource allocation. AI algorithms analyze vast datasets to detect anomalies, predict security threats, and enhance decision-making. These technologies enable organizations to manage security risks, improve operational efficiency, and deliver personalized user experiences. ...Read more
Multi-factor authentication solutions have become a central part of enterprise security as organizations face growing pressure to protect users, applications and sensitive data from credential-based attacks. Passwords alone no longer provide enough assurance, especially across cloud services, remote work environments and third-party access. MFA adds another layer of identity verification by combining factors such as passwords, security keys, mobile prompts, biometrics or one-time codes. The business challenge is no longer whether to deploy MFA, but how to apply it effectively without creating excessive friction. Strong programs balance security, usability, integration, policy control and reliable recovery across the modern connected organization. Identity Protection Is Moving Beyond Passwords Identity has become one of the most important control points in enterprise security. Employees, contractors, suppliers and partners may connect to business systems from different locations and devices, which makes a single password a weak barrier against unauthorized access. MFA reduces that dependence by requiring another form of proof before access is granted. The strongest deployments start with risk rather than technology. Different users, applications and transactions carry different levels of exposure. Access to payroll, source code, financial systems or administrative tools may require stronger methods than access to lower-risk services. Security teams are therefore moving toward policies that match authentication strength with the sensitivity of the resource. Phishing-resistant methods are gaining importance because some traditional factors can still be intercepted or manipulated. Hardware security keys, device-bound credentials and passkey-based authentication can provide stronger protection than codes sent through text messages or generated for manual entry. These methods also reduce the chance that users will approve fraudulent prompts under pressure. Adaptive authentication adds another layer of control. Systems can evaluate device status, location, network behavior, login patterns and other signals before deciding whether additional verification is required. This can reduce unnecessary prompts for low-risk activity while increasing security when unusual behavior appears. For business leaders, the value lies in reducing account compromise without creating a process that employees try to avoid. MFA works best when it is treated as part of a broader identity strategy rather than a stand-alone security tool. Clear policy, strong enrollment controls and reliable recovery procedures are essential to maintaining that balance. Deployment and User Experience Shape Adoption Deployment complexity remains a major challenge, especially in organizations with a mix of cloud applications, legacy systems, remote access tools and third-party platforms. Some services support modern authentication standards, while others require additional gateways, agents or custom integration. Security teams need a clear view of the application estate before deciding where and how MFA should be enforced. Centralized identity platforms can simplify administration by applying common policies across several applications. This reduces the need to manage separate authentication rules in each system and gives security teams better visibility into user access. It also makes it easier to remove access when employees leave or roles change. User experience has a direct effect on adoption. Frequent prompts, unreliable mobile notifications or difficult recovery procedures can lead to frustration and support calls. Poorly designed MFA can even encourage risky workarounds. Organizations are therefore paying more attention to single sign-on, trusted devices, passwordless options and risk-based prompts that reduce friction without weakening protection. Enrollment and recovery are particularly sensitive points. Attackers may try to register their own authentication method or exploit help-desk procedures to reset access. Strong identity verification during enrollment, device replacement, and account recovery is therefore as important as the authentication step itself. Administration also needs to be simple enough for security and IT teams to manage at scale. Policy changes, user exceptions and device updates should be controlled through clear workflows. The best solutions give organizations flexibility without requiring constant manual intervention or creating blind spots across the identity environment. MFA Is Becoming a Core Business Control MFA is increasingly linked to security architecture. Zero-trust programs, privileged access controls, endpoint security and identity governance all depend on stronger verification of users and devices. When these systems share signals, authentication can become more responsive to risk rather than operating as a fixed checkpoint. Integration with security monitoring is also becoming more valuable. Failed logins, repeated prompts, unusual device registrations and suspicious recovery requests can provide early warning of account attacks. Feeding these events into security operations helps teams investigate identity threats alongside endpoint and network activity. Business continuity is another important consideration. Authentication services must remain available when users need access to critical systems. Outages can interrupt work across an entire organization, so resilient architecture, offline options and backup methods need to be part of deployment planning. Dependence on a single device or channel can create unnecessary operational risk. Cost management is also shaping buying decisions. License fees are only one part of the investment. Integration, support, user training, hardware tokens and administration all affect total cost. Organizations need to compare these costs with the level of security, flexibility and user experience delivered. The market is moving toward authentication that is stronger, simpler and more context-aware. Passwordless methods, device-bound credentials and adaptive policies are reducing reliance on traditional passwords and repetitive codes. However, technology alone will not solve identity risk. Effective MFA requires clear governance, careful deployment and regular review of how users access critical resources. ...Read more

Weekly Brief