Extensions and Endpoint Devices

What Is Provisioning?

Provisioning (automatic setup) is the way a phone receives its settings from the server as it powers on, instead of someone typing them in by hand on each device.

ProvisioningAuto provisioningRemote setupZero-touch

Reading time: about 9 minutes

The problem it solves

For an IP phone to work, you have to enter quite a few details into it: the PBX server address, the extension number, a username, a password, the menu language, the time zone, extension keys, ringtones. On one phone that's ten minutes of typing. On twenty phones it's a whole morning — with a good chance of getting one digit wrong in the password of one of them.

And what happens when you want to change something? For example, add an extension key for a new employee on all the team's phones. Without automatic configuration, you go phone by phone, and in an institution with several buildings that also means walking between buildings.

Provisioning reverses the process: each phone's settings are stored in a central place, and the phone pulls them on its own. The English word means "supplying" — the server "supplies" the phone with what it needs in order to work.

How it works, step by step

The details vary between manufacturers, but the principle is similar on almost all phones:

  1. The phone powers on and gets a network address from the router (IP address).
  2. It looks for where to get its settings. There are several ways: an address preconfigured in it at the factory or by the provider, an address the router gave it along with the IP address, or a manufacturer's service that identifies the device by its unique number.
  3. It downloads a settings file — usually one general file for all phones, and another one specific to it, identified by the device's physical address (MAC).
  4. It applies the settings and restarts if needed.
  5. It registers with the PBX with the extension and password it received — and is ready for calls.

The important implication: the settings don't "live" inside the phone, but in a file that sits outside it. The phone is only the one that carries them out. So you can replace a device, reset it or move it to another place — and its identity as an extension is preserved. This is the same idea behind an extension on a cloud PBX: the extension is the configuration, and the device is just the way to answer on it.

From the side of the person connecting the phone, the whole process looks like this: connect a network cable, wait a minute or two, and the phone displays the extension name. Some call this Zero-touch — "no touching."

What gets configured this way

  • Extension details — server, username, password.
  • Keys — extension keys (BLF), speed dial, voicemail.
  • Language, date and time — menus in Hebrew, the correct time zone.
  • Audio settings — ringtones, volume, codecs.
  • Network settings — for example a separate VLAN for phones.
  • Software version — the phone can check whether there is an update and install it.
  • Security — locking the settings menu, an admin password for the device.

Manual vs. automatic

Manual setupAutomatic setup
A new phoneYou type everything on the device or in its interfaceYou connect it to the network — and it's configured
A change for all phonesYou go device by deviceYou change it in one place
A phone that was resetYou configure it again from scratchIt returns to its settings after startup
Chance of errorHigh, especially with passwordsLow — the same file for everyone
Best forA single phone, testingAny office with more than a few phones

Real-life examples

  • A broken phone. At an office in Bnei Brak, the reception phone fell and broke. You connect a replacement phone, and it gets the same extension and the same keys — as if nothing happened.
  • A new employee. A salesperson joins. You add him to the extension keys of the whole team — in one place, and the phones update.
  • An office move. You pack up the phones, connect them at the new office, and they pull their settings again.
  • An employee working from home. A phone is sent to the employee's home. He plugs it into the router, and the phone connects by itself, without the employee needing to understand any settings.

What to know about security

The settings file contains the extension's password. Whoever gets hold of it can impersonate the extension and make calls at your expense (toll fraud). That is why, in a proper auto-provisioning setup, the files travel over an encrypted connection, are password-protected, and are delivered only to a device that is correctly identified.

It is also a good idea to lock the settings menu on the device itself. A phone whose settings anyone can open is a phone where someone will change something "just for a moment."

When a phone won't connect: what to check

  • Is there power and network? The network lights on the phone's jack should be on. On a phone that gets power from the network cable, a dark screen usually means the switch isn't providing PoE or the cable is faulty.
  • Did the phone get an address? On most phones you can see the IP address in the menu. If there is no address, the problem is in the network, not in the settings.
  • Is the network blocking it? A strict firewall on the organization's network can block the settings download or the registration to the PBX.
  • Is it the right device? If the settings are tied to the physical address of a specific device, a different phone connected in its place won't receive them until the assignment is updated.
  • Did someone make a manual change? A manual change in the phone's interface can conflict with the settings it pulls, or be erased at the next startup.

In most cases, restarting the phone once the network is working solves the problem: the phone pulls the settings again and registers. And if that doesn't help either, it is better to contact the provider than to try to fix it through the device's menus.

What is inside the settings profile

The settings file — or "profile" — is simply a long list of lines in the style of "parameter = value." In most systems it is built in layers, so that you don't have to rewrite everything for every device:

  • The general layer — whatever is true for all the phones in the organization: the PBX address, time zone, language, default ringtone, network and security settings, and which software version to run.
  • The model layer — how many keys there are, where the transfer key is, how big the screen is. A phone with two keys and a phone with forty don't get the same layout.
  • The device layer — identified by the phone's physical address (MAC): the extension number, username and password, the name shown on the screen, and the BLF keys for this particular station.

When the phone pulls the files, the more specific layer takes priority over the general one. That way a single change in the general layer (for example, a new ringtone) reaches all the phones, without touching the other layers.

An example of typical content for a secretary's station profile (in generic names, not in the syntax of any particular manufacturer):

  • Server: the PBX address, and which server to check for updates
  • Account: extension 201, screen name "Secretary's Office," password
  • Keys 1–8: BLF for extensions 101, 102, 110–115
  • Key 9: voicemail box; key 10: speed dial to the courier
  • Audio: ringer volume, which codecs are allowed and in what order
  • Network: a VLAN for telephony, priority marking for voice packets
  • Administration: the device's admin password, menu lock, when to check for updates (for example, every night at three)

And when does the phone check whether there is anything new? At startup, and usually also at a fixed interval or at a fixed hour at night. That is why a change made at noon doesn't always arrive right away — sometimes a restart is needed, and sometimes you wait for the night.

Monday: day-to-day operation

The installation is one day. What shows whether auto-provisioning really works is everything that happens after it:

  • A broken phone. You take a replacement device from stock, update the system so the extension now belongs to the physical address of the new device, and connect a cable. Within a minute or two the screen shows the extension. You check in the "Extensions" screen that it is registered and from which device. The old device — reset it to factory settings before it leaves the office, so the password doesn't leave with it.
  • Moving desks. Two approaches: "the phone goes with the person" — you disconnect, move, plug into the new jack, and nothing changes. Or "the phone stays at the desk" — you swap the extension assignment between the two devices in the system, and each of the two people gets his own extension at the new location without carrying anything.
  • A new employee. You create an extension, assign it to a device from stock, and add it to the team's BLF keys — all in one place. The other phones get the new key at the next check or after a restart.
  • An employee who left. You delete or disable the extension, and assign the device to the next person. Don't leave a live extension with a password that someone outside the organization may know.
  • A version update for all phones. In the general layer you set a new version and a time at night. The phones download and install when no one is talking. It is better to run it first on one phone for a day or two.

Example: an office of 15 stations opens in one morning. The phones arrived in boxes, each with a sticker showing the employee's name and extension number, because the assignment was done in advance. The technician goes desk by desk: a network cable from the wall to the phone, and a short cable from the phone to the computer (most phones pass the network through). By the time he finishes the last row, the first ones already show names. A final round: open the "Extensions" screen and check that 15 out of 15 are registered. One extension isn't — the cable in the wall wasn't connected to the patch panel. A one-minute fix, and the office is running before ten.

Security in depth: where the dangers are

The previous section on security stated the main point: the file contains passwords. Here is what follows from that in practice:

  • The physical address is not a secret. A MAC address is printed on the sticker on the back of the phone, and addresses from a particular manufacturer can be guessed in sequence. A provisioning server that hands over a file to anyone who asks "in the name of" a certain address is a server that hands out passwords. That is why real identification is needed: a username and password for the server, or a digital certificate embedded in the device at the factory, which many phones have.
  • Encryption in transit. The file travels over an encrypted connection (HTTPS), not over open protocols that anyone on the network can read.
  • The phone's own interface. Every IP phone has an admin page in the browser. If its password is the manufacturer's default, anyone on the network can read the extension details from it. A strong admin password for each device is part of the profile.
  • A device that disappeared. A phone that was stolen or "forgotten" by a former employee stays registered to the extension. The right action is to change the extension's password on the PBX — the old device loses access, and the replacement device gets the new password through auto-provisioning.
  • Network separation. Phones on their own VLAN, so that an infected computer in the office can't reach them directly.
  • Unneeded services. Menus that allow remote connection to the device, or access without a password, are disabled in the profile.

The risk we are trying to prevent is toll fraud: someone who gets hold of the extension details dials abroad through it at night, and the bill comes to you. A well-organized auto-provisioning setup reduces this risk, because no one types passwords, sends them by email, or writes them on a note.

How it works with us at Kesher

All the phones, adapters and gateways we supply arrive already configured: the extension, the password and the extension keys — everything in place. You connect a network cable, and the device is ready.

For every extension the system generates a strong password, so there is no need to invent passwords or type them. In the "Extensions" screen of the control panel you can see whether each extension is registered and from which device — the quick way to confirm that a new phone has connected.

Need to change something — a key for a new employee, an extension's name, a replacement phone for a device that broke? You can ask us, and we will make the change. And for any question, a person answers you, not an automated system.

FAQ

What is provisioning on an IP phone?

It is automatic configuration: the phone downloads its settings from a server when it powers on, instead of someone typing them into the device.

What happens if I factory-reset the phone?

A phone that works with auto-provisioning usually pulls its settings again at the next startup. If not, contact the provider that set it up.

Can I buy a phone in a store and connect it to the PBX?

Technically, any phone that supports SIP can connect, but then it has to be configured. It is worth checking in advance with your PBX provider that the model is supported.

Is auto-provisioning a security risk?

It is safe when the files travel over an encrypted connection and are delivered only to the identified device. With a careless setup, a file with passwords can end up in the wrong hands.

Do I need a computer or a technician to connect a phone set up this way?

No. You connect a network cable (and power, if needed), wait a minute or two, and the phone shows the extension. A technician is needed only if there is a problem in the network itself.

How often does the phone check for new settings?

At startup, and usually also at a fixed interval or at a fixed hour at night, depending on the configuration. An urgent change arrives right after the phone is restarted.

I changed something in the phone's menu — will it stay?

Not necessarily. At the next check, the settings from the server may overwrite the change. A permanent change is made in the central location, not on the device.

Can I bring a phone that was with another provider?

Sometimes. Many phones remain "locked" to the previous provider's provisioning server even after a reset, and pull settings from it at every startup. You need to release the assignment with the previous provider or on the device, and check that the model is supported.

What is the difference between auto-provisioning and a cloud extension?

The extension is the identity on the PBX — a number, a name, routing, a voicemail box. Auto-provisioning is the way a physical device receives the details so it can answer on that extension. The same extension can move from one device to another.

Back to the Knowledge Center — all terms

Want to hear how it would work for you?

Tell us how your phones work today — how many calls, who answers, what gets in the way — and we'll get back to you with an organized proposal.

Leave your details and we'll get back to you
077-921-9000