New VDI solution for Teams

The new VDI solution for Teams is a new architecture for optimizing the delivery of multimedia workloads in virtual desktops.

System requirements

Requirement Minimum version
Teams -24193.1805.3040.8975 (for Azure Virtual Desktop/Windows 365)
-24295.605.3225.8804 (for Citrix)
-25198.1109.3837.4725 (for Amazon)
-MAC endpoints require 26072.521.4595.7966 or higher
-26072.521.4595.7966 (for Omnissa)
Azure Virtual Desktop/Windows 365 -Windows App for Windows: 2.0.352.0
-Remote Desktop Client for Windows: No longer supported. Upgrade to the latest Windows App.
-Windows App for MAC: 11.3.4 Non-App Store version. Users must use the stand-alone .pkg file, which can auto-update. Store version isn't supported.
-Evergreen link to the latest MAU client: https://aka.ms/RDMacMAU
Citrix -Virtual Desktop Agent (VDA): 2203 Long Term Service Release (LTSR) Cumulative Update (CU) 3 or 2305 Current Release (CR)
-Citrix Workspace app (CWA) for Windows: 2203 LTSR (any cumulative update), 2402 LTSR, or 2302 CR.
-MsTeamsPluginCitrix: 2024.41.1.1 (for Windows)
-Citrix Workspace app for MAC: 2508.10
-MsTeamsPluginCitrix: 2025.49.x.x (for MAC) aka.ms/macplugin
-Only CWA versions not at End of Life are supported
Amazon WorkSpaces Client 5.31.0.5733. WSP (Server Agent) 2.1.0.1840
Omnissa Horizon Client for Windows 8.17 or higher
Endpoint -Windows 10 1809 (SlimCore minimum requirement)
-Windows Enterprise Long Term Service Channel Thin clients on Windows 10 2019/2021, or Windows 11 2024 are supported
-GPOs must not block MSIX installations (see Step 3: SlimCore MSIX staging and registration on the endpoint)
-Minimum CPU: Intel Celeron (or equivalent) @ 1.10 GHz, four Cores, Minimum RAM: 4 GB
-macOS 14, 15 or 26 (requires CWA 2511)

Components

Component Role Update Size Notes
Teams vdiBridge Server-side virtual channel module. New version with every Teams version. Bundled with Teams.
Custom virtual channel (VC) Custom VC owned by Microsoft Teams. Stable API - no updates foreseen. Check the Citrix Studio policy Virtual channels allow list.
Plugin Client-side VC dll. Responsible also for SlimCore download and clean-up. Not frequent (ideally no updates). Approximately 600 KB. Bundled with Windows Remote Desktop Client 1.2.5405.0, Windows App for Windows 1.3.252, and Windows App for MAC 11.3.4 MAU client or higher.
Citrix CWA 2402 for Windows or higher can fetch and install the plugin. CWA 2508.10 for MAC
Bundled with Amazon WorkSpaces client 5.31.0.5733 for Windows or higher.
Bundled with Omnissa's Horizon Client 8.17 (2512) for Windows or higher
SlimCore Media engine (operating system specific, not VDI vendor specific). Auto-updated to a new version with each new Teams version. Approximately 50 MB. MSIX package hosted on Microsoft's public Content Delivery Network.

Optimizing with new VDI solution for Teams

Step 1: Confirm prerequisites

  1. Make sure you have the new Microsoft Teams version 24193.1805.3040.8975 or higher (for Azure Virtual Desktop/Windows 365), 24295.605.3225.8804 or higher for Citrix, or 26032.206.4355.6508 for Omnissa.

  2. Enable Teams policy if necessary for a specific user group (it's enabled by default at a Global org-wide level).

  3. For Citrix, you must configure the Virtual channels allow list as described in the Citrix Virtual channel allow list section of this article.

  4. For Amazon WorkSpaces, make sure the WorkSpace client for Windows is 5.31.0.5733 or higher.

  5. For Omnissa Horizon, optimization is now generally available - make sure the Horizon client for Windows is 8.17 (2512) or higher.

Step 2: Plugin installation on the endpoint

  1. For Azure Virtual Desktop and Windows 365, MsTeamsPluginAvd.dll is bundled with the Remote Desktop Client for Windows 1.2.5405.0, with the Windows App Store app for Windows 1.3.252 or higher, and with the Windows App for MAC Non-Store version 11.3.4

    • The plugin is found in the same folder location where the Remote Desktop Client is installed. You can find the plugin at AppData\Local\Apps\Remote Desktop or C:\Program Files (x86), depending on the mode in which it was installed.
    • The Windows App Store app, which is MSIX-based, is found in C:\Program Files\WindowsApps. Access to this folder is restricted.
  2. For Amazon WorkSpaces, MsTeamsPluginAmazon.dll is bundled with the WorkSpaces Client for Windows 5.28.0.5487 or higher.

    • The plugin is found in the same folder location where the WorkSpaces Client is installed.
  3. For Omnissa Horizon, MsTeamsPluginOmnissa.dll is bundled with the Horizon Client for Windows 8.17 (2512) or higher.

    • The plugin is found in the same folder location where the Horizon Client is installed (C:\Program Files\Omnissa\Omnissa Horizon Client).
  4. For Citrix Workspace app for Windows 2402 or higher, MsTeamsPluginCitrix.dll can be installed either:

    • Using the user interface when installing Citrix Workspace app:

      On the Add-on(s) page, select the Install Microsoft Teams VDI plug-in checkbox, and then select Install.

      Agree to the user agreement that pops up and proceed with the installation of the Citrix Workspace app.

      Note

      Citrix Workspace app for Windows 2402 only presents the plugin installation UI on a fresh install.
      For in-place upgrades to also present this option, Citrix Workspace app for Windows 2405 or Mac 2603 higher is required.
      Automatic installation of the plugin when CWA is auto-updating was introduced in CWA for Windows 2508.
      Starting from Citrix Workspace app 2603 for Windows, CWA can auto-update the plugin to the latest version, even before CWA auto-updates to a newer version.
      For more information, check this Citrix article

    • Via command line or scripts for managed Windows devices using C:>CitrixWorkspaceApp.exe /installMSTeamsPlugin

  • Admins can also install the plugin manually on top of any existing supported Citrix Workspace app (see System Requirements) using tools like SCCM (use the Windows app package deployment type) or Intune (use the Line-of-Business app).

    Admins can use msiexec with appropriate flags, as discussed in msiexec.

    Important

    • Windows Plugin MSI download link for Citrix customers:
      - For 32-bit Workspace app aka.ms/plugin.
      - For 64-bit Workspace app (new) aka.ms/plugin_x64.
      - For arm-based Workspace app https://aka.ms/plugin_arm64.
      - Citrix Workspace app (wfica process) can only load plugins from the same architecture (in other words, 32-bit CWA loading 64-bit DLL will fail to optimize)
    • Mac Plugin download link for Citrix customers aka.ms/macplugin
  • The plugin MSI automatically detects the CWA installation folder and places MsTeamsPluginCitrix.dll in that location.

  • Plugins can only be upgraded while there's no active Virtual Desktop session.

  • Plugins can't be downgraded, only upgraded or reinstalled (repaired).

  • Per-user installation of CWA isn't supported.

  • If no CWA is found on the endpoint, installation is stopped.

User type Installation folder Installation type
Administrator 64-bit: C:\Program Files (x86)\Citrix\ICA Client
32-bit: C:\Program Files\Citrix\ICA Client
Per-system installation
Release note version Details
2026.29.1.4 July 2026
-Fixed MSIX provisioning and registration issues for thin clients or kiosk devices that prevented new users from getting optimized with the new architecture.
-Only split MSIX packages are supported from this plugin version forward.
-Security enhancements
2026.15.1.1 April 2026
-Improved client-side watchdog reliability to reduce false disconnects and ensure more stable recovery from transient network interruptions.
-Support for Teams as a Published Apps (Citrix Virtual Apps)
2025.43.1.1 November 2025
-Improvements in virtual channel handling and transport.
-Improvements in MSIX installation process (download location updated to localappdata when temp is unavailable). Enhanced reliability in BITS downloader.
-Logging and telemetry fixes for improved diagnostics
2025.29.1.2 August 2025
-Additional logging and telemetry capabilities
2025.24.1.3 July 2025
-Thin Clients that use Unified Write Filters with RAM Overlay might experience SlimCore MSIX installation errors if TEMP/TMP Environment (System) variables are pointed to a RAM disk. This plugin fixes this problem. For more details, check the Unified Write Filters (UWF) section later in this article. It additionally supports HID disabling by creating a registry key in the Virtual Machine (see section 'Peripherals in VDI')
2025.14.1.8 May 2025
-The Citrix plugin can now download SlimCore packages that are 64-bit, increasing performance and improving screen sharing experiences. This release also supports the SlimCore split MSIX package when Teams is 25094.x.x.x or higher, simplifying user prompts for camera and microphone permissions. See "New Split MSIX Package" in Step 3: SlimCore MSIX staging and registration on the endpoint.
2024.41.1.1 October 2024
-When using SlimCore in multimonitor setups, a Citrix user is unable to share entire screen or individual monitors.
-Attempts a Reset-AppxPackage if SlimCoreVdi MSIX package registrations fail after the virtual channel is established.
2024.32.X.X August 2024
-The plugin now attempts a Reset-AppxPackage for SlimCoreVdi MSIX package in the event the AppExecution alias is missing.

Step 3: SlimCore MSIX staging and registration on the endpoint

The plugin silently executes this step, without user or admin intervention. The staging and registration relies on the App Readiness Service (ARS) on the endpoint. It's possible that registry keys set by a Group Policy or a third-party tool block the MSIX package installation. For a complete list of applicable registry keys, see How Group Policy works with packaged apps - MSIX.

Important

New Split MSIX Package A new 64-bit Slimcore installer is available, which splits the media engine installation into two different MSIX Packages, called Host and Framework. This change has direct implications on AppLocker/WDAC/Group Policy Objects (GPO), if configured on the user's device:

  • Host packages (~100 KB) [Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe] are in charge of registering SlimCore as an application in the Windows OS, under a single Package Family Name (PFN) - this appears as "Microsoft Teams VDI Optimizer" under Settings/Apps/Installed apps. Once users grant permissions for camera/microphone/location to this app, they won't be prompted again. This addresses a limitation with the previous SlimCore MSIX installer, which had different PFNs, hence every time Teams was upgraded in the VM it retriggered a user prompt for peripheral access. MsTeamsVdi.exe loads from the Host package, and it remains as the process in charge of all network communications.

  • Framework packages (~60 MB) [Microsoft.Teams.SlimCoreVdiFwk.win-x64.<version>_8wekyb3d8bbwe] only contain Real Time Media libraries. These packages have different PFNs, with versioning. They aren't visible under Apps/Installed apps. Multiple Framework packages can coexist in the same endpoint. MsTeamsVdi.exe automatically loads the Framework package that matches the Teams version on the VM.

  • Minimum System Requirements:
    AVD/W365 environments with Teams 25153.x.x.x and Remote Desktop client 1.2.6278 / Windows App 2.0.550.0.
    Citrix environments with Teams 25094.x.x.x and plugin 2025.14.1.8

The following registry keys could block new media engine MSIX package installation:

Important

Managed endpoints/thin clients with BlockNonAdminUserInstall enabled can still allow SlimCore packages to install. Apply KB5052094 (Windows 11 23H2 and 22H2), KB5052093 (Windows 11 24H2), KB5055612 (Windows 10 22H2), or any subsequent KB. This installation introduces a new Group Policy called "Allowed package family names for non-admin user install" in the Local Group Policy Editor:

Group Policy Editor -> Computer Configuration -> Administrative Templates -> Windows Components -> App Package Deployment -> Administrators can then Allow-list SlimCore packages by allowing a complete Package Family Name (for example, Microsoft.Teams.SlimCoreVdi.win-x64.2024.43_8wekyb3d8bbwe) or use Regex (for example, Microsoft.Teams.SlimCoreVdi.*_8wekyb3d8bbwe).

For the new Split MSIX Package architecture, the two new packages must be added to the allow-list (Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe and Microsoft.Teams.SlimCoreVdiFwk.*_8wekyb3d8bbwe).
This can also be achieved using Regex: Microsoft.Teams.SlimCoreVdi*.*_8wekyb3d8bbwe

Important

If AllowAllTrustedApps is disabled, the new media engine (MSIX) installation fails. This issue is fixed in the following Windows cumulative updates:

These three registry keys can be found at either of the following locations on the user's device:

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModelUnlock
  • HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx

Some policies might change these registry keys and block app installation in your organization because the admins set a restrictive policy. Some of the known GPO policies that could prevent installation include:

  • Prevent non-admin users from installing packaged Windows apps.

  • Allow all trusted apps to install (disabled).

Note

AppLocker or Windows Defender Application Control can also prevent MSIX package installation. AppLocker is a defense-in-depth security feature and not considered a defensible Windows security feature. Use Windows Defender Application Control when the goal is to provide robust protection against a threat and there you expect no by-design limitations to prevent the security feature from achieving this goal.

Important

Make sure there's no blocking configuration or policy, or add an exception for SlimCore MSIX packages in Local Security Policy -> Application Control Policies -> AppLocker. AppLocker can't process trailing wildcards, unlike Windows Defender Application Control. Since old SlimCoreVdi Packages or new Framework packages contain a version-specific PackageFamilyName (for example, Microsoft.Teams.SlimCoreVdi.win-x64.2024.36_8wekyb3d8bbwe or Microsoft.Teams.SlimCoreVdiFwk.win-x64.2025.14_2025.14.1.4_x64__8wekyb3d8bbwe), customers can add AppX or MSIX exclusions by relying on the PublisherID 8wekyb3d8bbwe instead. New Host packages are single Package Family Names (Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe).

Administrators using the more granular per-application 'AllAppList' to define the list of applications that are allowed to run need to add exceptions in this manner (since SlimCore follows the UWP model):

<App AppUserModelId="Microsoft.Teams.SlimCoreVdi.<platform>-<architecture>.<release_version>_8wekyb3d8bbwe!MsTeamsVdi" />

For the old MSIX installer: &lt;App AppUserModelId="Microsoft.Teams.SlimCoreVdi.win-x86.2025.12_8wekyb3d8bbwe!MsTeamsVdi" /&gt;.
For the new Split MSIX architecture: &lt;App AppUserModelId="Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe!MsTeamsVdi" /&gt;.

To find a list of released SlimCore packages, check this table.

Mac endpoints

Note

Mac is now rolled out 100% to General Availability for AVD/W365 and Citrix environments.

Users that meet the minimum requirements described earlier in this article can be optimized using the new architecture (SlimCore-based).

AVD and Windows 365 customers must use the nonstore Windows App version (also known as the Microsoft AutoUpdate or MAU client), since only that version bundles the Plugin. App Store Windows App doesn't include the Plugin, therefore users will remain in the WebRTC-based optimization. Evergreen link to the latest MAU client: https://aka.ms/RDMacMAU

For Citrix customers, CWA 2508.10 can present a User Interface upon installation that prompts the user to install the Plugin, but this flow requires user action. CWA 2603 also supports plugin deployment via Global App Config Service, or the Virtual Channel Plugin Download Manager policy in Citrix Studio.
An upcoming version of CWA (2607) will automatically install the Plugin. Administrators can also deploy the Plugin using other tools like JAMF.

Important

  • The Plugin is in charge of virtual channel establishment and automatic and silent media engine installation on the Mac device.
  • The Plugin for Mac also bundles the Host SlimCore MSIX Package. Therefore, the SlimCore package that is fetched and installed on macOS is the Framework only ('Microsoft.Teams.SlimCoreVdi.mac-arm64'). Multiple versions can coexist on the same user device. Microsoft Teams version on the VM dictates to the plugin which SlimCore version is needed.
  • All these activities are transparent to the user and the Administrators.
  • Location: /Applications/Utilities/MsTeamsVdi.Plugin.app

SlimCoreVdi installation folder

  • For AVD/W365, /Users/{USER}/Library/Containers/windows App/Data/Library/Application Support/Microsoft/TeamsVDI/Packages/
  • For Citrix, /Users/{User}/Library/Application Support/Microsoft/TeamsVDI/Packages

Log collection in Mac

Logs are stored in the following directory on the user's device: ~/Library/Application Support/Microsoft/TeamsVDI

Unsupported Features in Mac

  • HID​ (currently only available in Public Preview)
  • Townhall optimization as an attendee
  • For AVD/W365, Cross Cloud is currently not supported
  • Outgoing screen sharing in end-to-end encrypted meetings is disabled​
  • Share system audio
  • Authenticated Proxies in macOS Network settings (AVD/W365 only)
  • Link Layer Discovery Protocol (LLDP) in e911 (AVD/W365 only)
  • Remote App / Published Apps

Known Issues in Mac

  1. Presenter's mouse cursor is slow during app sharing. If the presenter stops and reinitiates app sharing, the lag is not present anymore. This is fixed in Teams 26149.x.x.x or higher.

  2. Zoom VDI plugin older than 6.6.10 on the Mac device results in a Citrix Workspace app crash on call transfers.

  3. If you attach/detach external monitors during the call, video might appear on the wrong screen. This also occurs when you change display alignments during the HDX session​.

Verifying that the endpoint is optimized

Once you meet all the minimum requirements, launching Teams for the first time will attempt to load in SlimCore optimized mode, by default.

You can check in the Teams client that you're optimized with the new architecture by looking at the VDI Status Indicator (top left in the UI). Also, users can select the ellipsis (three dots ...) on the top bar, then selecting Settings > About. The Teams and client versions are listed there.

  • AVD SlimCore Media Optimized = New optimization based on SlimCore.
  • AVD Media Optimized = optimization based on WebRTC.

The plugin (MsTeamsPluginAvd.dll, MsTeamsPluginCitrix.dll, or MsTeamsPluginAmazon.dll) is responsible for eventually downloading the media engine, and SlimCore, which is an MSIX package. It installs silently without admin privileges or reboots in (example, exact path varies):

C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdi.win-x64.2024.15_2024.15.1.5_x64__8wekyb3d8bbwe

For the new Split MSIX Package: C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdiFwk.win-x64.2025.28_2025.28.1.4_x64__8wekyb3d8bbwe C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdiHost.win-x64_2025.28.1.4_x64__8wekyb3d8bbwe

The remote desktop client or the Citrix Workspace app downloads the x64 or x86 SlimCore package, based on the user's device. The 'WindowsApps' folder is locked down, so users don't have access to it. Admins modify ACLs to take ownership, though this action isn't recommended. Instead, use PowerShell to list the MSIX apps in the endpoint:

PowerShellCopy

Get-AppxPackage Microsoft.Teams.SlimCore*

A sample of the results that can be returned from running this PowerShell is:

Name              : Microsoft.Teams.SlimCoreVdiHost.win-x64
Publisher         : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Architecture      : X64
ResourceId        :
Version           : 2026.20.1.7
PackageFullName   : Microsoft.Teams.SlimCoreVdiHost.win-x64_2026.20.1.7_x64__8wekyb3d8bbwe
InstallLocation   : C:\Program Files\WindowsApps\Microsoft.Teams.SlimCoreVdiHost.win-x64_2026.20.1.7_x64__8wekyb3d8bbwe
IsFramework       : False
PackageFamilyName : Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe
PublisherId       : 8wekyb3d8bbwe
IsResourcePackage : False
IsBundle          : False
IsDevelopmentMode : False
NonRemovable      : False
IsPartiallyStaged : False
SignatureKind     : Developer
Status            : Ok

Name              : Microsoft.Teams.SlimCoreVdiFwk.win-x64.2026.20
Publisher         : CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Architecture      : X64
ResourceId        :
Version           : 2026.20.1.7
PackageFullName   : Microsoft.Teams.SlimCoreVdiFwk.win-x64.2026.20_2026.20.1.7_x64__8wekyb3d8bbwe
InstallLocation   : C:\Program
                    Files\WindowsApps\Microsoft.Teams.SlimCoreVdiFwk.win-x64.2026.20_2026.20.1.7_x64__8wekyb3d8bbwe
IsFramework       : True
PackageFamilyName : Microsoft.Teams.SlimCoreVdiFwk.win-x64.2026.20_8wekyb3d8bbwe
PublisherId       : 8wekyb3d8bbwe
IsResourcePackage : False
IsBundle          : False
IsDevelopmentMode : False
NonRemovable      : False
IsPartiallyStaged : False
SignatureKind     : Developer
Status            : Ok

Important

Microsoft stores up to 12 versions of SlimCoreVdi Frameworks for compatibility purposes. We store these versions in case the user accesses different VDI environments, such as persistent, where Teams auto-updates itself, and non-persistent, where Teams auto-updates are disabled.

If you're optimized, you can see MsTeamsVdi.exe running on your endpoint for Azure Virtual Desktop/W365 (as a child process of msrdc.exe) or Citrix (as a child process of wfica32.exe). When using Process Explorer, If you select msrdc.exe (or wfica32.exe), select Show the lower pane under View and switch to the DLL tab, you can also see the Plugin (MsTeamsPluginAvd.dll or MsTeamsPluginCitrix.dll) being loaded. This action is a useful troubleshooting step in case you're not getting the new optimization.

VDI Status Indicator

Microsoft Teams displays information about the optimization status, helping the user understand if they're optimized or not. It also shows if they're using the WebRTC optimization or the new Slimcore-based one by hovering their cursor over the Optimized banner.

In cases where Microsoft Teams isn't optimized, the user sees a warning icon.

Screenshot of the Teams app showing it's not optimized.

Users can select the three dots and choose Optimize virtual desktop and restart to attempt a repair.

This selection triggers a Teams restart, which can solve some known issues. If the user is still unoptimized, an error code displays for quick diagnosis by IT Admins based on the connection error table.

Users are presented with a link to receive more information about the error, and if it's actionable, they can try a self-remediation.

Session roaming and reconnections

Note

If virtual desktop sessions are disconnected (not logged off, Teams is left running on the virtual machine), now Teams on Citrix can also switch optimization stacks without being restarted after reconnects. In other words, Teams tries to optimize the user with SlimCore if possible, and if the endpoint doesn't support it, WebRTC optimization is attempted.

For example, a Windows endpoint used in bring your own device (BYOD) scenarios while working from home that has the plugin installed, and a corporate-managed Linux thin client in the office that only supports WebRTC. When the user roams between the two endpoints, Teams will automatically pick the right optimization stack without asking the user to restart the application. Additionally, the user is notified about the optimization switch with a dismissible banner ("Optimizing virtual desktop ...").

This seamless stack transition replaced the modal dialogue that asked the user to manually restart the app in VDI environments.

Networking considerations

Tip

MsTeamsVdi.exe is the process that makes all the TCP/UDP network connections to the Teams relays/conference servers or other peers (both signaling and media).

SlimCore MSIX manifest adds the following rules to the Firewall: <Rule Direction="in" IPProtocol="TCP" Profile="all" /> <Rule Direction="in" IPProtocol="UDP" Profile="all" />

Important

In VDI environments where the new optimization is used alongside Conditional Access policies with Continuous Access Evaluation (CAE) and strict location enforcement, users may experience repeated Teams sign-in prompts or failed calls because authentication requests are evaluated against the endpoint (client) IP rather than the VM host IP, causing access to be blocked when connecting from untrusted networks. This behavior is by design and reflects stricter enforcement compared to WebRTC-based optimization. To mitigate impact, customers can relax CAE policies (e.g., avoid strict location enforcement), or add relevant endpoint or ISP IP ranges to trusted locations.

Note

Make sure the user's device has network connectivity (UDP and TCP) to endpoint ID 11, 12, 47 and 127 described in Microsoft 365 URLs and IP address ranges.
ID 184 is also required. The following table is a summary for reference only, monitor these two links (via RSS subscription) for the up-to-date list.

ID Category ER Addresses Ports Notes
11 Optimize required Yes 52.112.0.0/14, 52.122.0.0/15, 2603:1063::/38 UDP: 3478, 3479, 3480, 3481 Media Processors and Transport Relay 3478 (STUN), 3479 (Audio), 3480 (Video), 3481 (Screen share)
12 Allow required Yes *.lync.com, *.teams.microsoft.com, teams.microsoft.com, *.teams.cloud.microsoft, teams.cloud.microsoft, 52.112.0.0/14, 52.122.0.0/15, 2603:1027::/48, 2603:1037::/48, 2603:1047::/48, 2603:1057::/48, 2603:1063::/38, 2620:1ec:6::/48, 2620:1ec:40::/42 TCP: 443, 80, UDP: 443
47 Default required No *.office.net , graph.microsoft.com TCP: 443, 80 Used for SlimCore downloads and background effects
69 Default required No *.aria.microsoft.com, *.events.data.microsoft.com TCP: 443 Backend communication services
127 Default required No *.skype.com TCP: 443, 80
184 Default required No *.cloud.microsoft, *.static.microsoft, *.usercontent.microsoft TCP: 443, UDP 443 Used for Ringtones, Noise Suppression, and other Models

Network architecture

The network architecture of Teams VDI 2.

A walkthrough of the architecture in the diagram:

  1. Start Teams.​
  2. Teams client authenticates to Teams services. Tenant policies are pushed down to the Teams client, and relevant configurations are relayed to the app.​
  3. Teams detects that it's running in a virtual desktop environment and instantiates the internal vdibridge service​.
  4. Teams opens a secure virtual channel on the server​.
  5. The RDP/HDX/Blast/DVC protocol transports the request to the VDI Client (Windows App, Citrix Workspace app, Horizon Client, or Amazon WorkSpaces) that previously loaded MsTeamsPlugin (client-side virtual channel component)​.