Best practices

Last Updated : Aug 29, 2026 |
Prolog information
Avaya recommends that you implement the following tasks so that Avaya Workplace Client users have the best end-user experience:
Task
Notes
Use SIP instead of H.323 for all the user devices.
Avaya Workplace Client is a SIP client.
Avaya recommends the use of SIP so that users can use the advanced functionality that Avaya Workplace Client provides.
If H.323 is needed, users can perform dual-registration using a SIP endpoint. However, Avaya does not recommend the use of H.323 and dual-registration is supported as is.
Enable Multiple Device Access (MDA).
Deskphones and multiple clients can log in simultaneously.
For more information about MDA configuration, see Avaya Workplace Client settings in Avaya Aura Session Manager.
Use TLS for all connections.
Avaya recommends the use of TLS to provide security for all network connections.
For example, TLS is a must for presence, MDA, and Desk Phone mode.
Note:
If you are using the OAuth server for automatic configuration of Avaya Workplace Client, ensure that TLS 1.3 is enabled on Avaya Aura® Session Border Controller.
Configure settings for privacy and security.
If you configure the Exclusion feature on Communication Manager, users can maintain privacy of conversations and ensure that unwanted parties cannot join the call.
In the Manual Exclusion mode, the user presses the Exclusion button to activate and deactivate Exclusion. For more information, see Using Avaya Workplace Client for Android, iOS, Mac, and Windows
Automatic exclusion is a feature with which a user of a SIP or H.323 endpoint can prevent others with MDA of the same extension from bridging onto an existing call. For more information, see Avaya Workplace Client settings in Avaya Aura Communication Manager.
You can also enable the barge-in tone for a user extension on Communication Manager to warn users if someone else joins the call.
Enable automatic discovery of the automatic configuration URL using:
  • DNS-based discovery of the settings file for all platforms
  • Avaya accounts-based method
  • A parameter during installation for Mac or Windows if using an automated software distribution system and silent install
Use split-horizon DNS FQDN addresses.
Purpose is to send the Workplace traffic to the SBC when remote for security purposes, but not through the SBC when inside the enterprise network for performance and scaling purposes.
Use split-tunneling configuration when a VPN is in use.
Purpose is to send the Workplace traffic to the SBC when remote, even if the user is logged into VPN for other data security purposes. It is to keep the Workplace traffic outside the VPN to improve the network quality and the networking experience.
Use private trust store and automatic configuration to distribute certificates.
Useful if using certificates that are not issued by a CA with a certificate already in the device OS.
For more information, see Certificate distribution.
Use Avaya Aura® Device Services to provide single credential sign-in.
Useful as it removes the need for the user to enter phone credentials.
For more information, see Avaya Aura Device Services parameters
Use enterprise credentials for authentication.
Based on your environment, you can use Avaya Authorization Service or unified login or Integrated Windows Authentication (IWA).
Avaya Authorization Service is an authorization mechanism that enables users to authenticate using a combination of enterprise credentials and other factors that the enterprise has chosen, including enterprise Single Sign-On (SSO) and multi-factor authentication.
Unified login is a feature with which users can use the same set of credentials for accessing two or more services in Avaya Workplace Client. You can use unified login with your enterprise credentials from Active Directory or LDAP.
Avaya recommends the use of unified login for all services to avoid potential issues with credentials management.
Note:
If a server tends to report false failures for password authentication, Avaya recommends that you do not configure that server with Unified Login. You can then easily differentiate between these types of failures from Unified Login failures.
For more information, see Unified Login parameters.
If you want to remove the authentication step for the client, use Integrated Windows Authentication (IWA).
On mobile platforms, only configure the telephony methods that you require.
Useful as it simplifies the configuration as much as possible.
Use E.164 dial plans.
Avaya recommends the use of E.164 dial plans for new deployments.
For more information about Avaya Workplace Client dial plans, see Avaya Workplace Client Overview and Specification for Android, iOS, Mac, and Windows.