📜 ⬆️ ⬇️

Getting Started with Intel Active Management (AMT)

This document provides information on how to get started with Intel Active Management Technology (Intel AMT). It contains an overview of the capabilities of this technology, information about system requirements, Intel AMT client configurations, and development tools available for building applications that support Intel AMT.



Intel AMT supports remote applications running under Microsoft Windows * or Linux *. Intel AMT 2.0 or later supports only local Windows applications. For a complete listing of system requirements , see the Implementation Guide and the Intel AMT Reference Guide .

Getting started


To remotely manage an Intel AMT client or run examples from the SDK, use a separate system to remotely manage an Intel AMT device. For more information, see the Implementation Guide and the Intel AMT Reference Manual , located in the Docs folder in the Intel AMT SDK.
')

What is Intel Active Management?


Intel AMT is part of the Intel vPro solution package. If the platform supports Intel AMT, then such platforms can be remotely controlled regardless of the state of the power supply and the presence or absence of the operating system.
The Intel AMT system is based on the core of the Converged Security and Manageability Engine (CSME). Intel AMT is a component of Intel vPro and uses a number of elements of the Intel vPro platform architecture. In fig. 1 shows the relationship between these elements.


Figure 1. Intel Active Management Technology Architecture 11

Note the network connection associated with the Intel Management Engine (Intel ME). The adapter used varies depending on the version of Intel AMT used.


Intel AMT stores the following information in flash memory (Intel ME data).


New features in the Intel Active Management Technology version 11.0 SDK



Setting up an Intel AMT client


Preparing an Intel AMT client for use


In fig. Figure 2 shows the steps to configure an Intel AMT device before using it.


Figure 2. Setting progress

Before you configure an Intel AMT device in the Setup and Configuration Application (SCA), you must prepare it, having received the initial information, and put it into installation mode. The initial information will vary depending on the available components of the Intel AMT release and the platform settings applied by the OEM manufacturer. Table 1 lists installation and configuration procedures for different versions of Intel AMT.
Installation MethodApplicability to Intel AMT versionsadditional information
Traditional mode1.0; versions 2.x and 3.x in traditional modeTraditional installation and setup
SMB2.x, 3.x, 4.x, 5.xInstallation and configuration in SMB mode
PskFrom version 2.0 to Intel AMT 10, abolished in Intel AMT 11Install and configure using PSK
PKI2.2, 2.6, 3.0 and later versionsInstall and configure using PKI (remote configuration)
Manually6.0 and laterManual installation and setup (from version 6.0)
CCM, ACM7.0 and laterClient control mode and admin control mode
Manually configure clients for Intel AMT 7.0 and later
Table 1. Installation methods depending on the version of Intel AMT

Intel Setup and Configuration Software (Intel SCS) 11 can be used to prepare systems for earlier versions up to Intel AMT 2.x. For more information about Intel SCS and training levels available for different versions of Intel AMT, see the website Download the latest Intel Setup and Configuration Service (Intel SCS) .

Manual Tips


When setting up the platform manually, starting from version 6.0, there are no restrictions on the components, but certain features of the system behavior should be taken into account.


Starting with Intel AMT 10, some devices are shipped without a physical network adapter. These devices cannot be configured using existing USB solutions included with Intel SCS 11.

Manual installation


When enabled, the Intel AMT platform displays the BIOS startup screen, then processes the MEBx. During this process, you can access Intel MEBX, but this approach depends on the manufacturer of the BIOS. Some possible methods are:


Client control mode and admin control mode


After installing a device with Intel AMT 7.0 or later, it switches to one of two control modes.


There is also a configuration method that includes the procedure for changing the mode: from client mode to administrator mode. This procedure assumes that the Intel AMT device is in client control mode, and switches the device to administrator control mode.

In the administrator control mode, the Intel AMT functionality is not limited. This is due to a higher level of trust with this installation method.

Customer Management Restrictions


Upon completion of the simple host-based configuration, the platform enters the client control mode, in which the following restrictions apply.


Manually configure the Intel AMT 11.0 client


When you turn on the Intel AMT platform, the BIOS initial screen is displayed, then the BIOS extensions are processed. Logging into the Intel AMT extension in BIOS depends on the BIOS manufacturer.

When using the Intel AMT reference platform (SDS or SDP), you are prompted to press the <Ctrl + P> keys. After that, control passes to the main menu of the CSME.

In OEM systems, a one-time boot menu can be used, and logging into CSME is usually one of the boot options in this menu. The specific key combinations may vary depending on the OEM manufacturer, type of BIOS and model.

Configure Intel AMT 11.0 Clients Manually with Wi-Fi Only


Many systems no longer have a physical connector for connecting to a wired LAN. You can configure and activate Intel ME, then use the web interface or some other method to configure your wireless settings.

  1. Change the default password by setting a new value (this is required to continue). The new value must be a strong password. It must contain at least one uppercase letter, one lowercase letter, one digit and one special character, and its length must be at least eight characters.

    1. Log in to CSME at startup.
    2. Enter the default password (admin).
    3. Enter and confirm a new password.

  2. Select "Intel AMT Setup."
  3. Make sure the checkbox “Select Management Components” is checked.
  4. Select "Enable Network Access."
  5. Select "Y" to confirm the inclusion of the interface.
  6. Select "Network Setup".
  7. Select the Intel ME Network Name setting.

    1. Enter the node name.
    2. Enter the domain name.

  8. Select User Consent.

    1. The default is "KVM only". You can select “No” or “All”.

  9. Exit CSME.
  10. Set up a wireless connection using ProSet wireless drivers synchronization, a web interface, or another method.

Configuring Intel AMT 11.0 Clients Manually with Local Area Connection


Enter the default CSME password (admin).

Change the default password (required to continue). The new value must be a strong password. It must contain at least one uppercase letter, one lowercase letter, one digit and one special character, and its length must be at least eight characters. Using the management console, you can change the Intel AMT password without changing the CSME password.

  1. Select "Intel AMT Setup."
  2. Make sure the checkbox “Select Management Components” is checked.
  3. Select "Enable Network Access."
  4. Select "Y" to confirm the inclusion of the interface.
  5. Select "Network Setup".
  6. Select the Intel ME Network Name setting.

    1. Enter the node name.
    2. Enter the domain name.

  7. Select User Consent.

    1. The default is "KVM only". You can select “No” or “All”.

  8. Exit CSME.

Access to Intel AMT via a web interface


An administrator with user rights can establish a remote connection to an Intel AMT device through a web interface. To do this, enter the URL of the device. The URL will vary depending on whether TLS is enabled.


To connect without TLS, you can also use a local connection and a host browser. You can specify localhost or 127.0.0.1 as the IP address. Example: 127.0.0.1 : 16992.

Requirements for Intel AMT support


In addition to properly configuring the BIOS and CSME, an Intel AMT-compatible wireless network adapter is required. To manage a host's OS using Intel AMT, certain drivers and services are required.

To ensure that the drivers and Intel AMT services are loaded correctly, locate them in the device manager and in the "Services" section of the host OS. Regularly visit the OEM site for updated BIOS, firmware and driver versions.

Here are the drivers and services that should be displayed in the host OS.


* Versions of the network controller and wireless interface will vary depending on the generation of the Intel vPro platform.
** As part of the complete driver package for Intel MEI (chipset).
*** HID device drivers are required when connecting via Intel AMT KVM. There are usually no problems with the default drivers, but we encountered difficulties when using non-standard OS installations. If a connection is established to a device without HID drivers, the OS attempts to automatically install these drivers. After installation, re-establish the KVM connection.

Note. The driver version level must match the firmware and BIOS version level. If incompatible versions are installed, Intel AMT will not work with components that require these interfaces.

Physical device - wireless Ethernet connection


By default, all wireless vPro wireless platforms will have an Intel AMT-enabled wireless network card, such as the Intel AC 8260 dual-band adapter. Other wireless adapters other than Intel adapters will not support Intel AMT wireless connectivity. When using a wireless network adapter other than Intel AC 8260, you can use ark.intel.com to verify that this adapter is compatible with Intel AMT.

Required software for Windows


For remote control, device drivers are not required, but they are necessary for local data exchange with the firmware. OS discovery and configuration features require the Intel MEI driver, the SOL driver, the LMS service, and the Intel MSS application.

Device Drivers - Intel Management Engine Interface


An Intel MEI is required to connect to the firmware. By default, the Intel MEI driver is automatically installed from Windows Update. The version level of the Intel MEI driver should be the same as that of the Intel MEBX.

The Intel MEI driver is displayed in the device manager in the "System devices" section called the Intel Management Engine Interface.

Device Drivers - LAN Serial Driver


The SOL driver is used in the IDE redirection operation when connecting a remote CD-ROM drive.

The SOL driver is displayed in the device manager in the "Ports" section titled "Intel Active Management Technology - SOL (COM3)".


Figure 3. Serial LAN driver

Service - Intel Active Management Technology LMS Service


The Local Manageability Service (LMS) runs locally on an Intel AMT device and enables local management applications to send requests and receive responses. The LMS responds to requests sent to the local Intel AMT host and sends them to Intel ME using the Intel MEI driver. The service installer is in the same package as the Intel MEI drivers on the OEM websites.

Please note that when installing Windows, Windows Update only installs the Intel MEI driver. IMSS and LMS are not installed. The LMS service communicates from an OS application with the Intel MEI driver. If the LMS service is not installed, go to the OEM website and download the Intel MEI driver, which is usually in the chipset driver category.


Figure 4. Intel Management Engine Interface Driver

LMS is a Windows service installed on Intel AMT 9.0 or later. Previously, in versions of AMT AMT from 2.5 to 8.1, the LMS service was called User Notification Service (UNS).

The LMS receives a set of alerts from an Intel AMT device. The LMS writes an alert to the Windows application event log. To view alerts, right-click Computer and select Computer Management> System Software> Event Viewer> Application .

Application - Intel Management and Security Status


You can open the Intel MSS application using the blue key icon in the Windows notification area.


Figure 5. Intel Management and Security Status icon in the notification area

General tab


The General tab in Intel MSS displays the status of the Intel vPro components available on this platform and the event log. Each tab provides additional information.


Figure 6. General tab in Intel Management and Security Status

Intel AMT tab


Here, a local user can perform KVM and media redirection operations, use the help request and view the security status of the system.


Figure 7. Intel AMT tab in Intel Management and Security Status

Advanced tab


The Advanced tab in Intel MSS displays more detailed configuration information and Intel AMT components. In the screenshot shown in Fig. 8, it is clear that Intel AMT technology is configured on this system.


Figure 8. Advanced tab in Intel Management and Security Status

Intel Active Management Technology Software Development Kit (SDK)


The Intel AMT Software Development Kit (SDK) provides low-level programming capabilities, so developers can create management applications that best use Intel AMT.

The package of tools for developing software based on Intel AMT is a sample code and a set of API interfaces that allow developers to quickly and easily add support for Intel AMT to applications. The SDK also includes a complete set of documentation in HTML format.

This software development toolkit supports C ++ and C # on Microsoft Windows and Linux operating systems. The user manual and Readme files in each directory contain important information about building examples.

An SDK is a collection of folders that can be copied to any location. In this case, the entire folder structure should be copied, this is due to the mutual dependence between the components. At the top level are three folders: DOCS (contains documentation for the SDK), as well as folders with code examples for Linux and Windows. For more information on how to get started and use the SDK, see the Implementation Guide and the Intel AMT Reference Guide .

For more information about system requirements and sample code building, see the "Using the Intel AMT SDK" section in the Implementation Guide and the Intel AMT Reference Guide. Documentation is available on the Intel Software Network: Intel AMT Based Software Development Kit (latest release) .

Other Intel AMT Resources


» Implementation Guide and Intel AMT Reference Guide
» Intel AMT SDK Downloadable File
»High-level API, article and downloadable file
»Intel Platform Solutions Manager, article and download
» Power Shell module, downloadable file
» KVM Application Developer Guide
» Redirect Library
» CIM C ++ Platform API
» CIM C # Platform API
» WMI Intel ME Provider
» System Status Check (NAP)
» Case Studies and Projects

application


The following table lists the features supported in Intel AMT versions 8 through 11.
For a description of all features and components, see the Intel AMT Implementation Guide and Reference Manual (in the "Intel AMT Components" section.)
ComponentIntel AMT 8Intel AMT 9Intel AMT 10Intel AMT 11
Hardware inventoryXXXX
Persistent idXXXX
Remote on and offXXXX
SOL / IDE redirectionXXXX
Event managementXXXX
Third-party data warehousesXXXX
Embedded web serverXXXX
Flash ProtectionXXXX
Firmware updateXXXX
HTTP Digest / TLSXXXX
Static and dynamic IP addressesXXXX
System protectionXXXX
Agent presenceXXXX
Power management policiesXXXX
Mutual authenticationXXXX
Kerberos *XXXX
TLS-PSKXXXAbolished
Privacy iconXXXX
Wake on Intel Management Engine LANXXXX
Remote setupXXXX
Wireless setupXXXX
EAC 802.1XXXX
Power PacksXXXX
Environment detectionXXXX
Scope of reading the event logXXXX
System Heuristic ProtectionXXXX
WS-MAN interfaceXXXX
VLAN settings for Intel AMTXXXX
Network interfacesXXXX
Quick Help Call (CIRA)XXXX
Access monitorXXXX
Microsoft NAP support *XXXX
Virtualization support for agent presenceXXXX
PC alarm clockXXXX
KVM remote controlXXXX
Synchronize wireless profilesXXXX
IPv6 supportXXXX
Host based trainingXXXX
Proper shutdownXXXX
WS-Management APIXXXX
SOAP commandsXAbolishedAbolishedAbolished
InstantGo SupportX
Remote secure wipeX

Source: https://habr.com/ru/post/310318/


All Articles