Teams Rooms camera stops working after your IT team updates firewall rules. The camera shows as unavailable in the Teams Rooms console, and calls fail to send video. This usually happens because the firewall blocks the media ports Teams Rooms uses for webcam streams. This article explains the root cause, gives step-by-step fixes for the firewall and device, and covers related issues like audio failure and sign-in errors.
Key Takeaways: Restoring Teams Rooms Camera After Firewall Changes
- Teams Rooms media ports UDP 3478-3481 and TCP 443: These ports must be open for camera video to flow to Teams.
- Teams admin center > Teams devices > Teams Rooms > Restart: Restart the room device to reinitialize the camera after firewall rule changes.
- Teams Rooms Pro Management portal > Device health: Check the camera health report to confirm the camera is detected by the system.
Why a Firewall Change Breaks the Teams Rooms Camera
Teams Rooms uses a set of network endpoints and ports to send and receive media. The camera sends video over the User Datagram Protocol, or UDP, on ports 3478 through 3481. When a firewall rule blocks these ports, the Teams Rooms device cannot transmit the webcam stream. The camera appears as unavailable because the device cannot establish a media session with the Teams service.
Firewall changes often affect the media path even when the sign-in and control traffic still work. Sign-in uses Transmission Control Protocol, or TCP, on port 443. That port is usually left open. But the media ports are separate. If your network team adds a rule that restricts UDP traffic, the camera stops working.
Another factor is the Teams Rooms device’s network profile. If the device is on a guest network or a VLAN that has stricter rules, the camera may fail even though the main office network is fine. The device also needs to reach the Teams media relay servers. These servers are part of Microsoft’s global network. The firewall must allow outbound UDP to these servers.
Check the Teams Rooms Network Requirements
Before you change any firewall rule, verify the exact endpoints and ports required. Microsoft publishes a list of URLs and IP ranges for Teams. The media ports are UDP 3478 through 3481. The device also uses TCP 443 for signaling and TCP 443 for the control channel. You must allow outbound traffic to the Teams media relay IP ranges. The ranges are updated frequently, so use the official Microsoft 365 IP ranges web service to get the current list.
Steps to Diagnose and Fix the Camera After a Firewall Change
Follow these steps in order. Each step checks a different part of the system. Do not skip the firewall check even if the camera works after a restart.
- Verify the firewall rule for UDP 3478-3481
Open your firewall management console. Look for any rule that blocks UDP traffic on ports 3478 through 3481. If a new rule was added recently, edit it to allow outbound UDP to the Teams media relay IP ranges. Also allow inbound UDP responses on the same ports. Save the rule and apply it to the Teams Rooms device’s subnet. - Confirm the device can reach the Teams service
On the Teams Rooms console, go to Settings > Network. Check that the device shows a valid IP address and that the status shows connected. If the device reports a network error, fix the IP assignment or the VLAN membership. The device must have internet access through the firewall. - Restart the Teams Rooms device
In the Teams admin center, go to Teams devices > Teams Rooms. Select the device and click Restart. Wait for the device to come back online. A restart clears temporary network sessions that may have been broken by the firewall change. - Check the camera hardware connection
On the Teams Rooms device, unplug the USB cable from the camera and plug it back in. If the camera is connected through a hub, connect it directly to the device. The camera must be detected by the operating system. Look for the camera LED to light up. - Test the camera in the Teams Rooms settings
On the Teams Rooms console, go to Settings > Devices > Camera. Select the camera from the list. If the camera shows as unavailable, try a different USB port. If no camera appears, the driver may be missing. Reinstall the camera driver from the manufacturer’s website. - Use the Teams Rooms Pro Management portal for health checks
Sign in to the Teams Rooms Pro Management portal. Go to Device health and select the affected room. Check the camera health report. The report shows whether the camera is detected and if there are any errors. If the report shows a firmware issue, update the camera firmware. - Verify the Teams Rooms app version
On the device, check the app version in Settings > About. Compare it with the latest version listed in the Teams admin center. If the app is outdated, update it. An old app may not handle the network change correctly.
If the Camera Still Has Issues After the Main Fix
Teams Rooms Shows a Black Screen Instead of Video
A black screen usually means the camera is detected but not sending video. This can happen if the firewall allows the ports but blocks the media relay IP ranges. Check the firewall logs for dropped packets on UDP 3478-3481. If you see drops, add an allow rule for the specific IP ranges. Also check if the camera is covered by a privacy shutter.
Teams Rooms Camera Works in Meetings but Not in the Console Preview
This issue occurs when the console preview uses a different video pipeline. The meeting uses the media ports, but the preview may use a local service. Restart the device to reset the preview. If the problem persists, update the camera driver. The preview should show video within a few seconds of opening the camera settings.
Teams Rooms Cannot Sign In After the Firewall Change
Sign-in requires TCP 443 to reach the Teams service. If the firewall blocks this port, the device cannot authenticate. Check the firewall rule for outbound TCP 443. Also verify that the device can resolve the DNS name for Teams. Use the network settings on the device to test the connection. After fixing the rule, restart the device.
Teams Rooms Camera Is Detected But the Microphone Fails
Audio uses the same media ports as video. If the camera works but the microphone fails, the issue is likely the audio device, not the firewall. Check the microphone in Settings > Devices > Microphone. Make sure the correct microphone is selected. If the microphone is not detected, reinstall the audio driver.
Teams Rooms Desktop App vs Teams Rooms on Android: Camera Behavior
| Item | Teams Rooms on Windows | Teams Rooms on Android |
|---|---|---|
| Media ports | UDP 3478-3481 | UDP 3478-3481 |
| Sign-in port | TCP 443 | TCP 443 |
| Camera driver model | Uses Windows driver stack | Uses Android USB camera driver |
| Restart method | Teams admin center or physical button | Teams admin center or unplug power |
| Health monitoring | Teams Rooms Pro Management portal | Teams Rooms Pro Management portal |
Both platforms rely on the same network ports. The main difference is how the camera driver is handled. On Windows, you may need to reinstall the driver manually. On Android, the camera is usually plug-and-play. The firewall fix is identical for both.
You can now restore the Teams Rooms camera by checking the firewall rules, restarting the device, and verifying the camera hardware. Start with the UDP ports, then use the Teams admin center to restart the device. If the camera still fails, use the Teams Rooms Pro Management portal to check the device health report. For ongoing monitoring, set up alerts in the portal for camera errors. You can also use the Teams admin center to schedule automatic restarts for your rooms to prevent future issues.