<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.innovaphone.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tsbodry</id>
	<title>innovaphone wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.innovaphone.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Tsbodry"/>
	<link rel="alternate" type="text/html" href="https://wiki.innovaphone.com/index.php?title=Special:Contributions/Tsbodry"/>
	<updated>2026-08-28T16:01:14Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://wiki.innovaphone.com/index.php?title=Reference15r1:PBX/Config/General&amp;diff=80336</id>
		<title>Reference15r1:PBX/Config/General</title>
		<link rel="alternate" type="text/html" href="https://wiki.innovaphone.com/index.php?title=Reference15r1:PBX/Config/General&amp;diff=80336"/>
		<updated>2026-08-07T08:03:59Z</updated>

		<summary type="html">&lt;p&gt;Tsbodry: /* Common */   System wide Group is missing. Please insert a description and how2&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Configuration ==&lt;br /&gt;
&lt;br /&gt;
=== Common ===&lt;br /&gt;
&lt;br /&gt;
;PBX Mode: The PBX operating mode&lt;br /&gt;
:* &#039;&#039;&#039;Off&#039;&#039;&#039; - The PBX is disabled. After enabling the PBX a browser refresh is needed to activate additional PBX webpages.&lt;br /&gt;
:* &#039;&#039;&#039;Master&#039;&#039;&#039; - The PBX on this device acts as Master. Within a multisite installation exactly one PBX must be configured as Master.&lt;br /&gt;
:* &#039;&#039;&#039;Slave&#039;&#039;&#039; - The PBX on this device acts as Slave. Within a multisite installation several PBXes can be configured as Slave.&lt;br /&gt;
:* &#039;&#039;&#039;Standby&#039;&#039;&#039; - The PBX on this device acts as Standby for the Master. As long as the master is available, this PBX is  not active, but just monitors the Master. If the Master is not available this PBX is active.&lt;br /&gt;
:* &#039;&#039;&#039;Standby-Slave&#039;&#039;&#039; - The PBX on this device acts as Standby for a Slave. As long as the slave is available, this PBX is  not active, but just monitors the slave. If the slave is not available this PBX is active.&lt;br /&gt;
&lt;br /&gt;
;System Name: The system Name. On all PBX within a multisite installation the same System Name must be configured. For H.323 endpoints this name is the gatekeeper identifier, for SIP endpoints it is the server name.&lt;br /&gt;
&lt;br /&gt;
;Use as Domain: Uses the &#039;&#039;System Name&#039;&#039; as domain name, together with the name field in the user object the PBX constructs the email address (used for sending emails out ox myPBX). This mechanism is also used for Federation, to federate with other domains.&lt;br /&gt;
&lt;br /&gt;
;PBX Name: The name of the PBX on this device. With this name a PBX is associated to a node. The field &#039;Name&#039; (not Long Name) of a PBX Node object relates to this name.&lt;br /&gt;
&lt;br /&gt;
;DNS: DNS Name of the PBX. If configured this will be used for myPBX redirects if a client tries to register at a PBX on which the user is not configured.&lt;br /&gt;
&lt;br /&gt;
;Unknown Registrations: If this checkmark is set, the PBX accepts &#039;unknown&#039; registrations. This means registrations with no matching object configured. If from an endpoint registered in this way a number of an object is dialed, which has no registration active and no &#039;HW-ID&#039; configured the name used for the registration is configured as &#039;HW-ID&#039; of this object. This is an easy way to deploy large numbers of phones.&lt;br /&gt;
&lt;br /&gt;
:&#039;&#039;&#039;With PBX Pwd only:&#039;&#039;&#039; If checked only registrations with a PBX authentication or a verified certificate in case of H.323/TLS are accepted. In this case either &amp;quot;PBX Pwd&amp;quot; or &amp;quot;TLS only&amp;quot; is set in a device generated.&lt;br /&gt;
&lt;br /&gt;
;Reverse Proxy Addresses: Up to 8 IP-Addresses (Mixed IPv4 and IPv6 allowed, but no DNS names) can be entered in this field, separated by comma. Registrations from one of these addresses are assumed to be routed through a Reverse Proxy. To the address &#039;/&amp;lt;certificate name&amp;gt;&#039; can be added to also check the TLS certificate of the Reverse Proxy. If the reverse proxy certificate is to be verified, the certificate or the issuer of the reverse proxy certificate must be trusted in the PBX. (If you use a SAN certificate you have to enter the first SAN-Name)&lt;br /&gt;
:Checking only on the certificate is also possible, by omitting the IP-address, eg &#039;/*.domain.de&#039;. Registrations sent with this certificate are considered to be coming over the Reverse Proxy.&lt;br /&gt;
:If empty addresses are used, unauthenticated registrations from unknown or internal addresses are not allowed, but any registration must be authenticated, with a password or the certificate from the reverse proxy.&lt;br /&gt;
; Assume TLS: If the &#039;&#039;Assume TLS&#039;&#039; checkmark is set, it is assumed, that the reverse Proxy did a successful check of the TLS certificate against the registration name.&lt;br /&gt;
&lt;br /&gt;
;Media relay endpoint/Firewall public IP: For media relay endpoints (e.g. third party SIP phones) the public address of the firewall of the PBX network can be configured. This address is signaled in the SDP to received RTP from the phone. The firewall should have configured a port forwarding to the PBX or the TURN, for the RTP range of the PBX or TURN.&lt;br /&gt;
&lt;br /&gt;
;Media relay endpoint/TURN: If this checkmark is set, the PBX allocates TURN endpoints for calls to or from media relay endpoints, which registerd thru the reverse proxy (e.g. third party SIP phones)&lt;br /&gt;
&lt;br /&gt;
;IP address for App Platform&lt;br /&gt;
: The ip address of an App Platform can be configured here, with a DNS name used for it. If myApps uses a host to access the PBX different from the configured DNS name of the PBX, the hostname in any App url, which matches the configured AP DNS, is replaced by the AP IP. This way it is possible to configure a PBX with DNS names and access it with myApps when the DNS is not yet set up. If the checkmark &#039;&#039;Operation without DNS&#039;&#039; is set as well any matching DNS name is replaced also when an App service requests the URL of another App service (Example: Users requesting the URL of Devices for provisioning) and in the URL sent to the App services itself (Example: Devices uses this URL to construct the URL set at devices for the Devices registration).&lt;br /&gt;
&lt;br /&gt;
: Note that this mode is intended to be able to run the PBX using DNS names while the DNS is not yet in place. Once the DNS is up and running, neither the DNS name of the AP nor its IP address should be configured here.&lt;br /&gt;
&lt;br /&gt;
;Music On Hold URL: A URL for the Music On Hold. This file is read by the PBX using HTTP and sent to a held endpoint via RTP. The format of this URL is&lt;br /&gt;
&lt;br /&gt;
:&#039;&#039;&#039;&amp;lt;nowiki&amp;gt;http://&amp;lt;addr&amp;gt;/&amp;lt;file&amp;gt;.$coder?coder=g711a,g711u,g722,g723,g729,opus-nb,opus-wb&amp;amp;repeat=true&amp;lt;/nowiki&amp;gt;&#039;&#039;&#039;. &amp;lt;addr&amp;gt; is the IP address of the http server, no dns name is allowed here. &amp;lt;file&amp;gt; is the filename. $coder will be replaced by the actual coder used.&lt;br /&gt;
&lt;br /&gt;
:Parameters: &#039;&#039;coder=g729,g711a,g711u,g723,opus-nb,opus-wb&#039;&#039; is the list of available coders. Only these coders must be specified for which a corresponding file exists. &#039;&#039;repeat=true&#039;&#039; should be specified in order to loop the file endlessly. &#039;&#039;random=true&#039;&#039; can be used to start the music on hold on a random point (this will work only if the URL is not local though).&lt;br /&gt;
&lt;br /&gt;
:By default the built-in Music-On-Hold is played (Pseudo URL: &amp;quot;MOH?coder=g729,g711a,g723&amp;amp;repeat=true&amp;quot;).  You can also play a dial tone (Pseudo URL &amp;quot;TONE&amp;quot;) or a ring-back tone (Pseudo URL &amp;quot;TONE?tone=ringback&amp;quot;).&lt;br /&gt;
&lt;br /&gt;
:The maximum length of the URL is limited to 500 characters (bytes).&lt;br /&gt;
&lt;br /&gt;
:If you configure a wrong (or invalid) URL then you will have silence as MOH. To prevent this situation when the MoH for some specific context/user(see below) is missing and silence is played instead of any MoH, an additional parameter &#039;&#039;fallback=true&#039;&#039; is available. If the file provided in the URL is missing (HTTP Error 404 Not Found is delivered by the HTTP Server) and the parameter &#039;&#039;fallback&#039;&#039; is provided, the default MoH will be played instead of silence. To use a custom file as fallback MoH, instead of default MoH, any file name can be provided with the &#039;&#039;fallback&#039;&#039; parameter: e.g. &#039;&#039;fallback=other_filename&#039;&#039;. The file other_filename.g7xx must be placed in the same folder as a file provided with URL. A special filename &#039;&#039;fallback=ringback&#039;&#039; can be used to generate a ringback tone (equivalent to &#039;&#039;TONE?tone=ringback&#039;&#039;) instead to play an alternative file.&lt;br /&gt;
&lt;br /&gt;
:Within the URL %&amp;lt;id&amp;gt; can be used to put in some context information of the call. The information refers to the party which has put the receiving party on hold. For information about the receiving party itself, the id has to be preceded by &#039;.&#039; (e.g. &#039;&#039;&#039;.l&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
:&#039;&#039;&#039;l&#039;&#039;&#039; Long Name&lt;br /&gt;
:&#039;&#039;&#039;h&#039;&#039;&#039; Name (H.323 id)&lt;br /&gt;
:&#039;&#039;&#039;n&#039;&#039;&#039; Number&lt;br /&gt;
:&#039;&#039;&#039;N&#039;&#039;&#039; Node&lt;br /&gt;
:&#039;&#039;&#039;P&#039;&#039;&#039; PBX&lt;br /&gt;
:&#039;&#039;&#039;d&#039;&#039;&#039; Diverting Name&lt;br /&gt;
:&#039;&#039;&#039;#d&#039;&#039;&#039; Diverting Number&lt;br /&gt;
&lt;br /&gt;
: See [[Howto:Dynamic_MOH]] for more details on how to use dynamic music on hold.&lt;br /&gt;
&lt;br /&gt;
;External Music On Hold: To offload the device from playing the Music on hold, the Music On Hold can be played by a separate device. This device can register with a name configured here. To retrieve the Music On Hold a call is sent to this device. For each held endpoint a call is sent.&lt;br /&gt;
&lt;br /&gt;
;Response Timeout: Global timeout (in seconds) after which any action for no response is taken (e.g. Call Forward on No Response). A timeout configured at any object overrides this value.&lt;br /&gt;
&lt;br /&gt;
;Dial Complete Timeout: Global timeout (in seconds) after which any action for incomplete dialed number is taken (e.g. incomplete destination at trunk object).&lt;br /&gt;
&lt;br /&gt;
;No. of Regs w/o Pwd: Number of registration without password authentication which are allowed per user. If 0 is configured no registration without password is possible.&lt;br /&gt;
Pls. note that registrations from 127.0.0.1 w/o password will be accepted anyway&lt;br /&gt;
&lt;br /&gt;
;Security block time(s): Time for which a registration to a user is blocked after attempt with wrong password. Default is 20s. With a value of 0 this features is turned off.&lt;br /&gt;
&lt;br /&gt;
;Recall Timeout: A value configured here enables recall after transfer. If a call is transferred and not answered within this time, the call is sent back to the transferring endpoint.&lt;br /&gt;
&lt;br /&gt;
;Chat no Attachments: If checked, no file attachments are allowed in chats for any user&lt;br /&gt;
&lt;br /&gt;
;Retries on busy (14s): Number of retries (Each attempt runs for 14 seconds) of blind transfer to a busy endpoint, before a recall back to the initiator is executed. During an attempt, the PBX waits to see if the target is free, and then delivers the call. The default value are 4-retries if the field is empty. If there is a 0 configured no further (in addition to the initial) will be executed. (This function depends on the &#039;&#039;Recall Timeout&#039;&#039; so the &#039;&#039;Recall Timeout&#039;&#039; must not be empty)&lt;br /&gt;
&lt;br /&gt;
;Max Call Duration (h): Number of hours until a call with media is disconnected automatically. Affects all calls with initialized media channels signalled via PBX.&lt;br /&gt;
&lt;br /&gt;
;Group Default Visibility: Defines additional visibility for active group members. These are added to the visibility rights derived from the [[{{NAMESPACE}}:PBX/Objects/Visibility | Visibility settings]]  in user or template definitions. Note that changes made here only take effect after a re-registration.&lt;br /&gt;
&#039;&#039;&#039;System wide Groups&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
???&lt;br /&gt;
;Presence with Alert: Enable presentation of presence on phone upon alert. Setting applies for all PBX users.&lt;br /&gt;
&lt;br /&gt;
;Enable External Transfer: Unless this checkbox is set any attempt to transfer an external call back to an external destination will result in disconnection of the call.&lt;br /&gt;
&lt;br /&gt;
;No CLIR on Internal calls: If checked numbers are displayed even if received with presentation restricted. When sending a call presentation restricted can still be set and should be honored by a public network.&lt;br /&gt;
&lt;br /&gt;
;Media Relay:&lt;br /&gt;
:;Off: No Media Relay is done in the PBX &lt;br /&gt;
:;On: All media traffic is routed through the PBX.  With the &#039;&#039;&#039;No Media Relay if Addresses are identical or private&#039;&#039;&#039; checkmark, this is not done if the two call endpoints registration addresses are either private or equal (i.e. external endpoints behind the same NAT router).  To identify an address as private the &amp;quot;Private Networks&amp;quot; configuration from &#039;&#039;IP4/General/Settings&#039;&#039; is used.&lt;br /&gt;
:;Auto: Media traffic is routed through the PBX if calls are between private and public registration addresses but not for calls between private and private or public and public registration addresses. To identify an address as private the &amp;quot;Private Networks&amp;quot; configuration from &#039;&#039;IP4/General/Settings&#039;&#039; is used. In v11 this was the behaviour if &#039;&#039;RTP Proxy&#039;&#039; was &#039;&#039;on&#039;&#039;.&lt;br /&gt;
: Please note that when media relay is in effect for a call,  &#039;&#039;&#039;video is not working&#039;&#039;&#039;.   With ICE (available from v12r1), media relay in the PBX should be obsolete except for special applications.  Check &#039;&#039;On&#039;&#039; or &#039;&#039;Auto&#039;&#039; only if you need to have this, since it creates CPU load on the PBX.&lt;br /&gt;
&lt;br /&gt;
;Generate CDRs: If this checkbox is set, the PBX generates CDRs for all calls. For details, refer to the [[{{NAMESPACE}}:Concept_Call_Detail_Record_CDR_PBX|CDR description article]].&lt;br /&gt;
&lt;br /&gt;
;Reverse Lookup URL&lt;br /&gt;
: A String in the LDAP URL Format according [https://tools.ietf.org/html/rfc2255 RFC2255] which will be used by the PBX to make a lookup for all external numbers.&lt;br /&gt;
: Number resolutions will be forwarded to internal applications like generated CDRs, Phone App etc..&lt;br /&gt;
: Example: &#039;&#039;ldaps://ap.innovaphone.com/dc=entries?givenname,sn,company?sub?(metaSearchNumber=+%n)?bindname=innovaphone.com\contacts&#039;&#039;&lt;br /&gt;
:* dn:  &#039;&#039;dc=entries&#039;&#039;&lt;br /&gt;
:* attributes: &#039;&#039;givenname,sn,company&#039;&#039;&lt;br /&gt;
:* scope: &#039;&#039;sub&#039;&#039;&lt;br /&gt;
:* filter: &#039;&#039;(metaSearchNumber=+%n)&#039;&#039;&lt;br /&gt;
:** %n is a placeholder for the given cgpn&lt;br /&gt;
:* extension: &#039;&#039;bindname=innovaphone.com\contacts&#039;&#039;&lt;br /&gt;
:** The username for the authentication.&lt;br /&gt;
:&#039;&#039;&#039;Variables&#039;&#039;&#039;&lt;br /&gt;
:* %n - cgpn&lt;br /&gt;
:* %u - h323 name of the current object&lt;br /&gt;
:&#039;&#039;&#039;Password&#039;&#039;&#039;: Password to authenticate access for the used ldap source. Leave empty if not required.&lt;br /&gt;
: Examples for use of different ldap directories are listed in the [[{{NAMESPACE}}:Concept_Number_Resolution_and_LDAP#PBX_Configuration|Concept Article]]&lt;br /&gt;
&lt;br /&gt;
;Logo URL&lt;br /&gt;
:The URL to a customized logo image that will be displayed on the phones. Leave empty to keep the standard logo. The image size should be 220x150px or less with 24Bit color deep or less and an RGB range. The file format should be PNG or JPEG.&lt;br /&gt;
&lt;br /&gt;
;Route Root-Node External Calls to: Destination object (Long Name) of Root-Node external calls. This configuration option is available on the Master or Standby PBX only. Any call which cannot be terminated inside the PBX is sent to this destination as long as neither the source nor the destination of the call can be associated with a node with a PBX configured. This object must be assigned to this PBX.&lt;br /&gt;
:&#039;&#039;&#039;For calls from local PBX only&#039;&#039;&#039;: If set on a master, calls from a slave are not sent to this destination but sent back to the slave where the call came from. On the slave the call is then sent to a destination configured with &#039;Route Root-Node External Calls to&#039;.&lt;br /&gt;
&lt;br /&gt;
;Route PBX-Node External Calls to: Destination object (Long Name) of PBX-Node external calls. Any call which cannot be terminated inside the PBX is sent to this destination as long as the source nor the destination of the call can be associated with the node of this PBX. If a call is sent from or to an object defined inside the node of this PBX or in a node hierarchically below the node of this PBX the call is associated to the node of this PBX. This object must be assigned to this PBX, that is, it has to register to this PBX.&lt;br /&gt;
&lt;br /&gt;
;Route Internal Calls to: Destination object (Long Name) to which any call is sent for which a PBX internal destination was found, except for those calls that originated from that object. This can be used to apply special routing on PBX internal calls.&lt;br /&gt;
&lt;br /&gt;
;Escape Dialtone from: The PBX object (Long Name) to which a call is made to get a dialtone if a dialtone is configured for the escape of a node. As above, this object must be assigned to this PBX.&lt;br /&gt;
&lt;br /&gt;
;Prefix for Intl/Ntl/Subscriber/Area-Code/Country-Code: Prefixes to be used to map International, National and Subscriber numbers.&lt;br /&gt;
:* &#039;&#039;&#039;International Prefix&#039;&#039;&#039; (&amp;lt;code&amp;gt;000&amp;lt;/code&amp;gt; in Germany).&lt;br /&gt;
:* &#039;&#039;&#039;National Prefix&#039;&#039;&#039; (&amp;lt;code&amp;gt;00&amp;lt;/code&amp;gt; in Germany).&lt;br /&gt;
:* &#039;&#039;&#039;Subscriber&#039;&#039;&#039; (in Germany, &amp;lt;code&amp;gt;0&amp;lt;/code&amp;gt; is a commonly used trunk line access code).&lt;br /&gt;
::The SubscriberID is used for hotkey-actions within myAPPs-launcher. By use of node-objects, adjust the Subscriber Prefix in the respective [[{{NAMESPACE}}:PBX/Objects/Node#Number_Mapping_.28International.2C_National.2C_Subscriber_Prefix.29|node object number mapping]].&lt;br /&gt;
::For myPBX-launcher hotkeys, refer to the [[{{NAMESPACE}}:Phone/User/Directories#Dialing_location|dialing location settings]].&lt;br /&gt;
&lt;br /&gt;
:* &#039;&#039;&#039;Area-Code&#039;&#039;&#039; (in Germany for example, the town Mannheim has area code &amp;lt;code&amp;gt;621&amp;lt;/code&amp;gt;).&lt;br /&gt;
:* &#039;&#039;&#039;Country-Code&#039;&#039;&#039; (for Germany, &amp;lt;code&amp;gt;49&amp;lt;/code&amp;gt; would be used)&lt;br /&gt;
&lt;br /&gt;
: These settings resemble the same settings found in the [[{{NAMESPACE}}:PBX/Objects/Node | Node]]  and [[{{NAMESPACE}}:PBX/Objects/PBX | PBX]]  object. However, they apply to the &#039;&#039;root&#039;&#039; node instead (and should be consistent through all PBXs in a multi-PBX system).&lt;br /&gt;
&#039;&#039;&#039;Max. length internal number&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
In the phone and softphone App: If the number, witch is dialed is 7 digits or longer, the subscriber prefix is added. (A reset of the pbx and the myApps is needet after changes.)&lt;br /&gt;
;Adjust LDAP results for e.164: Add a &amp;quot;+&amp;quot; prefix to an PBX-internal LDAP-contact-search result. This is used for 3rd-party- and DECT-phones which are not able to benefit from the Dialing Location settings in case of LDAP-search in an E.164-setup. See also [[{{NAMESPACE}}:Concept_Number_Adjustments_%28Dialing_Location%29#PBX_database_used_as_LDAP_database|concept description]].&lt;br /&gt;
&lt;br /&gt;
;Tones: The tones scheme to be used for PBX generated dialtones. This applies to dialtones generated for node prefixes, ringback on transfer and some more.&lt;br /&gt;
&lt;br /&gt;
=== Slave PBX ===&lt;br /&gt;
&lt;br /&gt;
If the PBX is operated in Slave mode, then the Slave PBX section is displayed&lt;br /&gt;
&lt;br /&gt;
;Registration: The VOIP protocol used for the registration to the master. Possible choices are H.323, H.323/TCP or H.323/TLS.&lt;br /&gt;
&lt;br /&gt;
;Master: The IP address of the PBX master&lt;br /&gt;
&lt;br /&gt;
;License Only: If set, the PBX obtains license from master, but acts as master in all other respects.&lt;br /&gt;
&lt;br /&gt;
;Alternate Master: The IP address of an alternative PBX master (standby, if available)&lt;br /&gt;
&lt;br /&gt;
;Password: The password to be used for registration at the Master as configured in the corresponding PBX Object (The length of the password is limited to 16 characters)&lt;br /&gt;
&lt;br /&gt;
;Master GK-ID: The System Name/Gatekeeper ID of the PBX Master were will register (Optional, usually used for DynPBX).&lt;br /&gt;
&lt;br /&gt;
;Replication: This parameter allows you to select the replication style for the slave PBX: either &#039;&#039;All&#039;&#039; or &#039;&#039;Local&#039;&#039; (only users that need to be known in this PBX). For the replication process the [[Reference9:PBX/Config/Security|PBX Password]] is used which have to be the same password on all PBXes in the system.&lt;br /&gt;
&lt;br /&gt;
;dyn PBX ID: This parameter allows to set replication from a specific DynPBX configured on the Master Device.&lt;br /&gt;
&lt;br /&gt;
;Use local static User DB: A dynPBX has also this checkmark. The database of the main PBX is used, but be careful due to the increased memory usage. The dynPBX will create its own PBX datastructure which allocates memory.&lt;br /&gt;
&lt;br /&gt;
;Route Master calls if no Master to: If the master is not available, master calls are sent to this destination. Destination has to be an object with active registration.&lt;br /&gt;
&lt;br /&gt;
;Max Calls to Master/No Reroute: This parameter can be used to limit the calls to the master. If a call is sent to the master and there are already calls to/from the master equal to or exceeding this value, the call is rejected if &#039;&#039;&#039;No Reroute&#039;&#039;&#039; is set or is handled as if the master was not available otherwise.&lt;br /&gt;
&lt;br /&gt;
;License Limits: Here we can set limit of licensing for this Slave PBX for Port, Mobility, Operator and Softwarephone.&lt;br /&gt;
&lt;br /&gt;
For complete replication from master to slave, check also password in [[Reference9:PBX/Config/Security#PBX_password]]&lt;br /&gt;
&lt;br /&gt;
=== Standby PBX ===&lt;br /&gt;
&lt;br /&gt;
If the PBX is operated in Standby mode, then the Standby PBX section is displayed&lt;br /&gt;
&lt;br /&gt;
;Master: The IP address of the PBX master&lt;br /&gt;
&lt;br /&gt;
;Replicate from Master: Turns on full replication from the master PBX&lt;br /&gt;
&lt;br /&gt;
;use TLS: Use LDAPS (TLS) instead of LDAP (TCP).&lt;br /&gt;
&lt;br /&gt;
For complete replication from master to slave or standby, check also password in [[Reference9:PBX/Config/Security#PBX_password]]&lt;/div&gt;</summary>
		<author><name>Tsbodry</name></author>
	</entry>
	<entry>
		<id>https://wiki.innovaphone.com/index.php?title=Howto16r1:Configure_OAuth2_E-Mail&amp;diff=80153</id>
		<title>Howto16r1:Configure OAuth2 E-Mail</title>
		<link rel="alternate" type="text/html" href="https://wiki.innovaphone.com/index.php?title=Howto16r1:Configure_OAuth2_E-Mail&amp;diff=80153"/>
		<updated>2026-07-17T12:34:04Z</updated>

		<summary type="html">&lt;p&gt;Tsbodry: /* Example Redirect URIs */             &amp;quot;Fax&amp;quot; case sensitive matters&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The innovaphone PBX and apps can be configured to send E-Mails for various subjects and purposes. Major E-Mail providers intent to discontinue the username/password authentication schemes in favour of OAuth2. PBX and Apps version 16r1 does support OAuth2 authentication for SMTP. Here is a step by step guide how to set up OAuth2 support in Microsoft 365 through the Azure Portal and how to set it up on a Google Gmail account in the Google Cloud Console.&lt;br /&gt;
&lt;br /&gt;
== General Information ==&lt;br /&gt;
Most of the large email providers offer the possibility to define an app that is allowed to gain access of a certain scope like SMTP. &amp;lt;br&amp;gt;&lt;br /&gt;
It assigns a Client ID / Client Secret.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Authorization for sending from the mail account needs to be given one time either:&amp;lt;br&amp;gt;&lt;br /&gt;
* By providing resource owner username/password. Sending this to the token endpoint results in an access token and long term refresh token.&lt;br /&gt;
* By interactive authorization via a popup dialogue that is loaded from the authorization endpoint. After the credentials are verified, the dialogue redirects to the redirect URI with an authorization code that is traded to an access token and refresh token.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
The access token is sent for authentication in SMTP. It needs regular refresh, which will be done automatically.&lt;br /&gt;
&lt;br /&gt;
=== Modes ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Exchange&#039;&#039;&#039;: Microsoft, with interactive authorization&lt;br /&gt;
* &#039;&#039;&#039;Microsoft 365&#039;&#039;&#039;: Microsoft, without interactive authorization (Resource owner and password has to be filled)&lt;br /&gt;
* &#039;&#039;&#039;Gmail&#039;&#039;&#039;: Google, with interactive authorization&lt;br /&gt;
* &#039;&#039;&#039;Google Service Account&#039;&#039;&#039;:  Google, without interactive authorization (Client e-mail, Private Key ID and Private Key of the service account must be provided)&lt;br /&gt;
* &#039;&#039;&#039;Client secret post&#039;&#039;&#039;: Generic configuration where all parameters of the client secret post OAuth2 flow can be set.&lt;br /&gt;
* &#039;&#039;&#039;Private key jwt&#039;&#039;&#039;: Generic configuration where all parameters of the private key jwt OAuth2 flow can be set.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Example Redirect URIs ===&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;PBX&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-pbx.domain.com/OAUTH2-CLIENT/auth.htm&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;Reporting&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-ap.domain.com/domain.com/reporting/auth.htm&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;Fax&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-ap.domain.com/domain.com/&amp;lt;/nowiki&amp;gt;&#039;&#039;&#039;F&#039;&#039;&#039;ax/auth.htm&lt;br /&gt;
* &#039;&#039;&#039;Users&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-ap.domain.com/domain.com/usersapp/auth.htm&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;Connect&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-ap.domain.com/domain.com/messages/auth.htm&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
* &#039;&#039;&#039;AP Manager&#039;&#039;&#039;: &amp;lt;nowiki&amp;gt;https://example-ap.domain.com/manager/auth.htm&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Microsoft 365 ==&lt;br /&gt;
=== Azure Portal ===&lt;br /&gt;
Log in to Microsoft Azure Portal (https://portal.azure.com) and go to Microsoft Entra ID.&lt;br /&gt;
[[File:AzureMicrosoftEntraID.png|none|thumb|600x600px|/AzureMicrosoftEntraID.png|/AzureMicrosoftEntraID.png]]&lt;br /&gt;
Add a new app registration to create client credentials.&lt;br /&gt;
[[File:AzureAddAppRegistration.png|none|thumb|600x600px|/AzureAddAppRegistration.png|/AzureAddAppRegistration.png]]&lt;br /&gt;
Register the application and maybe already fill in the redirect URI for Web based application type to path OAUTH2-CLIENT/auth.htm at the PBX.&lt;br /&gt;
[[File:AzureRegisterAnApplication.png|none|thumb|600x600px|/AzureRegisterAnApplication.png|/AzureRegisterAnApplication.png]]&lt;br /&gt;
App registration is complete. Client ID and tenant needs to be configured at the PBX and every app that will be sending e-mails.&lt;br /&gt;
[[File:AzureApp.png|none|thumb|600x600px|/AzureApp.png|/AzureApp.png]]&lt;br /&gt;
Create a client secret. Note that expiry is limited to no longer than 2 years. The client secret must be renewed before expiry and the new secret configured and interactive authorisation carried out again to ensure continuous operation.&lt;br /&gt;
[[File:AzureAddClientSecret.png|none|thumb|600x600px|/AzureAddClientSecret.png|/AzureAddClientSecret.png]]&lt;br /&gt;
Copy the client secret. It also needs to be configured at the PBX and every app that will be sending e-mails.&lt;br /&gt;
[[File:AzureCopyClientSecret.png|none|thumb|600x600px|/AzureCopyClientSecret.png|/AzureCopyClientSecret.png]]&lt;br /&gt;
Add permissions located in APIs my organization uses.&lt;br /&gt;
[[File:AzureAddApiPermissionMyOrganization.png|none|thumb|600x600px|/AzureAddApiPermissionMyOrganization.png|/AzureAddApiPermissionMyOrganization.png]]&lt;br /&gt;
More precisely located in Office 365 Exchange Online.&lt;br /&gt;
[[File:AzureAddApiPermissionExchange.png|none|thumb|600x600px|/AzureAddApiPermissionExchange.png|/AzureAddApiPermissionExchange.png]]&lt;br /&gt;
And there in the application permissions.&lt;br /&gt;
[[File:AzureAddApiExchangeApplication.png|none|thumb|600x600px|/AzureAddApiExchangeApplication.png|/AzureAddApiExchangeApplication.png]]&lt;br /&gt;
Namely SMTP Mail.Send.&lt;br /&gt;
[[File:AzureAddApiSendMailAsUser.png|none|thumb|600x600px|/AzureAddApiSendMailAsUser.png|/AzureAddApiSendMailAsUser.png]]&lt;br /&gt;
Grant admin permission for Mail.Send.&lt;br /&gt;
[[File:AzureGrantApiPermissions.png|none|thumb|600x600px|/AzureGrantApiPermissions.png|/AzureGrantApiPermissions.png]]&lt;br /&gt;
API permissions are now granted.&lt;br /&gt;
[[File:AzureApiPermissionsGranted.png|none|thumb|600x600px|/AzureApiPermissionsGranted.png|/AzureApiPermissionsGranted.png]]&lt;br /&gt;
Tell all redirect URIs that the PBX and the apps will be using during interactive authorization.&lt;br /&gt;
[[File:AzureRedirectUris.png|none|thumb|600x600px|/AzureRedirectUris.png|/AzureRedirectUris.png]]&lt;br /&gt;
Allow public client flows of OAuth2. Resource Owner Password Credentials Flow has the advantage that it doesn&#039;t need interactive authorization.&lt;br /&gt;
[[File:AzureAllowPublicClientFlows.png|none|thumb|600x600px|/AzureAllowPublicClientFlows.png|/AzureAllowPublicClientFlows.png]]&lt;br /&gt;
&lt;br /&gt;
=== Microsoft 365 admin center ===&lt;br /&gt;
Log in to the Microsoft 365 admin center (https://admin.cloud.microsoft).&lt;br /&gt;
[[File:MS365AdminCenter.png|none|thumb|600x600px|/MS365AdminCenter.png|/MS365AdminCenter.png]]&lt;br /&gt;
Make sure that Microsoft 365 licenses are assigned to your user.&lt;br /&gt;
[[File:MS365UserLicenses.png|none|thumb|600x600px|/MS365UserLicenses.png|/MS365UserLicenses.png]]&lt;br /&gt;
Set your user active.&lt;br /&gt;
[[File:MS365ActiveUsers.png|none|thumb|600x600px|/MS365ActiveUsers.png|/MS365ActiveUsers.png]]&lt;br /&gt;
Locate the Mail tab of your user.&lt;br /&gt;
[[File:MS365UserEMail.png|none|thumb|600x600px|/MS365UserEMail.png|/MS365UserEMail.png]]&lt;br /&gt;
Allow authenticated SMTP.&lt;br /&gt;
[[File:MS365AuthenticatedSMTP.png|none|thumb|600x600px|/MS365AuthenticatedSMTP.png|/MS365AuthenticatedSMTP.png]]&lt;br /&gt;
&lt;br /&gt;
=== PBX Example configuration === &lt;br /&gt;
With this Microsoft setup the OAuth2 configuration for the resource owner password credentials flow can be filled in as follows. &lt;br /&gt;
[[File:OAuth2ResourceOwnerPasswordCredentials.png|none|thumb|600x600px|/OAuth2ResourceOwnerPasswordCredentials.png|/OAuth2ResourceOwnerPasswordCredentials.png]]&lt;br /&gt;
For interactive authorization this is the OAuth2 configuration. Authorize e-mail access one time and send a test mail to verify everything went well.&lt;br /&gt;
[[File:OAuth2InteractiveAuthorization.png|none|thumb|600x600px|/OAuth2InteractiveAuthorization.png|/OAuth2InteractiveAuthorization.png]]&lt;br /&gt;
&lt;br /&gt;
== Gmail ==&lt;br /&gt;
=== Preparations === &lt;br /&gt;
Login to the Google Cloud Console (https://console.cloud.google.com), select a project, New project.&lt;br /&gt;
[[File:GoogleSelectProject.png|none|thumb|600x600px|/GoogleSelectProject.png|/GoogleSelectProject.png]]&lt;br /&gt;
Create the project.&lt;br /&gt;
[[File:GoogleCreateProject.png|none|thumb|600x600px|/GoogleCreateProject.png|/GoogleCreateProject.png]]&lt;br /&gt;
Client credentials will be created in this project.&lt;br /&gt;
[[File:GoogleProjectCreated.png|none|thumb|600x600px|/GoogleProjectCreated.png|/GoogleProjectCreated.png]]&lt;br /&gt;
From the library specify the APIs needed to access.&lt;br /&gt;
[[File:GoogleApisServicesFromLibrary.png|none|thumb|600x600px|/GoogleApisServicesFromLibrary.png|/GoogleApisServicesFromLibrary.png]]&lt;br /&gt;
These are in the Gmail API.&lt;br /&gt;
[[File:GoogleApisServicesApiLibrary.png|none|thumb|600x600px|/GoogleApisServicesApiLibrary.png|/GoogleApisServicesApiLibrary.png]]&lt;br /&gt;
Choose the Gmail API and enable it.&lt;br /&gt;
[[File:GoogleGmailApis.png|none|thumb|600x600px|/GoogleGmailApis.png|/GoogleGmailApis.png]]&lt;br /&gt;
Credentials need to be created.&lt;br /&gt;
[[File:GoogleGmailApiAdded.png|none|thumb|600x600px|/GoogleGmailApiAdded.png|/GoogleGmailApiAdded.png]]&lt;br /&gt;
Invoke the help me choose wizard.&lt;br /&gt;
[[File:GoogleCreateCredentialsHelpMeChoose.png|none|thumb|600x600px|/GoogleCreateCredentialsHelpMeChoose.png|/GoogleCreateCredentialsHelpMeChoose.png]]&lt;br /&gt;
User data access is needed.&lt;br /&gt;
[[File:GoogleCredentialsUserData.png|none|thumb|600x600px|/GoogleCredentialsUserData.png|/GoogleCredentialsUserData.png]]&lt;br /&gt;
Configure the consent screen of the interactive authorization.&lt;br /&gt;
[[File:GoogleOAuthConsentScreen.png|none|thumb|600x600px|/GoogleOAuthConsentScreen.png|/GoogleOAuthConsentScreen.png]]&lt;br /&gt;
Specify the permissions that need to be authorized by the user.&lt;br /&gt;
[[File:GoogleOAuthScopes.png|none|thumb|600x600px|/GoogleOAuthScopes.png|/GoogleOAuthScopes.png]]&lt;br /&gt;
Its mail.google.com in general.&lt;br /&gt;
[[File:GoogleScopeMailGoogleCom.png|none|thumb|600x600px|/GoogleScopeMailGoogleCom.png|/GoogleScopeMailGoogleCom.png]]&lt;br /&gt;
And its to send email on the users behalf.&lt;br /&gt;
[[File:GoogleScopeAuthGmailSend.png|none|thumb|600x600px|/GoogleScopeAuthGmailSend.png|/GoogleScopeAuthGmailSend.png]]&lt;br /&gt;
These are the scopes needed.&lt;br /&gt;
[[File:GoogleScopes.png|none|thumb|600x600px|/GoogleScopes.png|/GoogleScopes.png]]&lt;br /&gt;
Ask client credentials for Web type application.&lt;br /&gt;
[[File:GoogleOAuthClientID.png|none|thumb|600x600px|/GoogleOAuthClientID.png|/GoogleOAuthClientID.png]]&lt;br /&gt;
Tell all redirect URIs that the PBX and the apps will be using during interactive authorization.&lt;br /&gt;
[[File:GoogleRedirectURIs.png|none|thumb|600x600px|/GoogleRedirectURIs.png|/GoogleRedirectURIs.png]]&lt;br /&gt;
Download the credentials. This json file contains all information for OAuth2 configuration.&lt;br /&gt;
[[File:GoogleClientCredentialsDownload.png|none|thumb|600x600px|/GoogleClientCredentialsDownload.png|/GoogleClientCredentialsDownload.png]]&lt;br /&gt;
Customize the OAuth consent screen&lt;br /&gt;
[[File:GoogleOAuthConsentScreenSettings.png|none|thumb|600x600px|/GoogleOAuthConsentScreenSettings.png|/GoogleOAuthConsentScreenSettings.png]]&lt;br /&gt;
Start the customization wizard.&lt;br /&gt;
[[File:GoogleConsentScreenWizard.png|none|thumb|600x600px|/GoogleConsentScreenWizard.png|/GoogleConsentScreenWizard.png]]&lt;br /&gt;
Choose which users may authorize.&lt;br /&gt;
[[File:GoogleAudienceExternal.png|none|thumb|600x600px|/GoogleAudienceExternal.png|/GoogleAudienceExternal.png]]&lt;br /&gt;
Google workspace users may choose internal audience. Users not in Google workspace proceed with external.&lt;br /&gt;
[[File:GoogleContactInformation.png|none|thumb|600x600px|/GoogleContactInformation.png|/GoogleContactInformation.png]]&lt;br /&gt;
Add a test user.&lt;br /&gt;
[[File:GoogleTestUserAdded.png|none|thumb|600x600px|/GoogleTestUserAdded.png|/GoogleTestUserAdded.png]]&lt;br /&gt;
&lt;br /&gt;
=== PBX Example configuration === &lt;br /&gt;
The OAuth2 parameters can be filled in with the information from the json file downloaded above. Authorize e-mail access one time and send a test mail to verify everything went well.&lt;br /&gt;
[[File:OAuth2InteractiveGmail.png|none|thumb|600x600px|/OAuth2InteractiveGmail.png|/OAuth2InteractiveGmail.png]]&lt;br /&gt;
&lt;br /&gt;
== Generic ==&lt;br /&gt;
&lt;br /&gt;
For other e-mail providers the client secret post OAuth2 flow may be configured in a generic way. Details need to be supplied by the e-mail provider.&lt;br /&gt;
&lt;br /&gt;
For the Microsoft 365 setup above it would be as follows with Token endpoint &#039;&#039;&amp;lt;nowiki&amp;gt;https://login.microsoftonline.com/af326a34-169c-469e-946b-1ef57925306b/oauth2/v2.0/token&amp;lt;/nowiki&amp;gt;&#039;&#039; Authorization URL &#039;&#039;&amp;lt;nowiki&amp;gt;https://login.microsoftonline.com/af326a34-169c-469e-946b-1ef57925306b/oauth2/v2.0/authorize?scope=https://outlook.office.com/SMTP.Send&amp;lt;/nowiki&amp;gt; offline_access&#039;&#039; The configuration appends &#039;&#039;&amp;amp;response_type=code&amp;amp;prompt=consent&amp;amp;login_hint=...&amp;amp;redirect_uri=...&amp;amp;client_id=...&#039;&#039; automatically.[[File:OAuth2ClientSecretPost.png|none|thumb|600x600px|/OAuth2ClientSecretPost.png|/OAuth2ClientSecretPost.png]]&lt;br /&gt;
For the Gmail example above the generic confguration would be like this with Token endpoint &#039;&#039;&amp;lt;nowiki&amp;gt;https://oauth2.googleapis.com/token&amp;lt;/nowiki&amp;gt;&#039;&#039; Authorization URL &#039;&#039;&amp;lt;nowiki&amp;gt;https://accounts.google.com/o/oauth2/auth?access_type=offline&amp;amp;scope=https://mail.google.com/&amp;lt;/nowiki&amp;gt;&#039;&#039; The configuration appends &#039;&#039;&amp;amp;response_type=code&amp;amp;prompt=consent&amp;amp;login_hint=...&amp;amp;redirect_uri=...&amp;amp;client_id=...&#039;&#039; automatically.&lt;br /&gt;
[[File:OAith2ClientSecretPostGmail.png|none|thumb|600x600px|/OAith2ClientSecretPostGmail.png|/OAith2ClientSecretPostGmail.png]]&lt;br /&gt;
The private key jwt OAuth2 flow can be configured generically as well.[[File:OAuth2PrivateKeyJWT.png|none|thumb|600x600px|/OAuth2PrivateKeyJWT.png|/OAuth2PrivateKeyJWT.png]]&lt;br /&gt;
&lt;br /&gt;
== Related Articles ==&lt;br /&gt;
* [[Reference16r1:PBX/Config/Authentication]]&lt;br /&gt;
* [[Reference16r1:Apps/PbxManager/Email]]&lt;br /&gt;
* [[Reference16r1:Concept App Connect#E-Mail configuration]]&lt;br /&gt;
* [[Reference16r1:Concept App Service Fax&amp;amp;action=edit&amp;amp;redlink=1#Mail Configuration (SMTP Server)|Reference16r1:Concept App Service Fax#Mail Configuration (SMTP_Server)]]&lt;br /&gt;
* [[Reference16r1:Concept App Service Reports&amp;amp;action=edit&amp;amp;redlink=1#Configuration|Reference16r1:Concept App Service Reports#Configuration]]&lt;br /&gt;
* [[Reference16r1:Concept App Service Users#Users Admin App (innovaphone-usersadmin)]]&lt;br /&gt;
* [[Reference16r1:Concept App Platform#SMTP]]&lt;/div&gt;</summary>
		<author><name>Tsbodry</name></author>
	</entry>
</feed>