<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Intel vPro Expert Center Blog</title>
    <link>http://communities.intel.com/community/openportit/vproexpert/blog</link>
    <description>Intel vPro Expert Center Blog</description>
    <pubDate>Thu, 05 Nov 2009 15:19:31 GMT</pubDate>
    <generator>Clearspace 2.5.9 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-11-05T15:19:31Z</dc:date>
    <item>
      <title>Known Issues wiki: LANDesk, MS ConfigMgr, Remote BIOS update, and more.</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2009/11/05/known-issues-wiki-landesk-ms-configmgr-remote-bios-update-and-more</link>
      <description>&lt;!-- [DocumentBodyStart:f915cce9-e153-45e8-b56c-41b30cc28d4a] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Here's a compilation of some of the issues that were added in the last few months to the &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Known Issues, Best Practices, and Workarounds&lt;/a&gt; wiki:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;LANDesk* 8.8 SP2 console requires repeated deletion of two directories when provisioning&lt;/a&gt; &lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Failure of collection-based power control in Microsoft* SCCM SP1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Intel&lt;sup&gt;®&lt;/sup&gt; MEBX, Web UI, and remote admin passwords are not automatically synchronized&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Tips on ME firmware updates&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Wrong IP address for Intel ME on Lenovo M58p using Hypervisor&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Intel(R) AMT does not allow multiple simultaneous commands&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Need to set LANDesk* root certificate as trusted certificate&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-external-small" href="/docs/DOC-1247;jsessionid=6C87AB7C62062604CE32CB83A35F219C.node3COMS#IntelR_SCS_is_only_supported_on_English_versions_of_Windows_Server_2008"&gt;Intel(R) SCS is only supported on English versions of Windows* Server 2008&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Usage of Locally Administered Address on Intel&lt;sup&gt;®&lt;/sup&gt; Active Management Technology enabled systems&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="Comm-Body" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/em&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f915cce9-e153-45e8-b56c-41b30cc28d4a] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">landesk</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">configmgr</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sccm</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">intel_amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <pubDate>Thu, 05 Nov 2009 15:19:31 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2009/11/05/known-issues-wiki-landesk-ms-configmgr-remote-bios-update-and-more</guid>
      <dc:date>2009-11-05T15:19:31Z</dc:date>
      <clearspace:dateToText>3 weeks, 2 days ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/known-issues-wiki-landesk-ms-configmgr-remote-bios-update-and-more</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=12772</wfw:commentRss>
    </item>
    <item>
      <title>Ctrl-Alt-Delete – Archiving Low-Tech Computer Fixes</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2009/07/28/ctrl-alt-delete-archiving-low-tech-computer-fixes</link>
      <description>&lt;!-- [DocumentBodyStart:7a641507-627b-4f90-8a3a-160fb631a8bb] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;A while back I was &lt;/span&gt;&lt;/span&gt;&lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/vproexpert/blog/2009/03/04/stop-vpro-from-making-memories-of-pop-pc-fixes"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;lamenting &lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;the fact that Intel vPro technology promises to end the need (at least among businesses at the moment) for all of the creative &lt;em&gt;low&lt;/em&gt;-tech fixes we all use when our PCs crawl onto the shoulder of the Internet and expire as if they've just ran out of electrons.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I asked you for your most useful low-tech fixes and many of you responded.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;We also made this video that &lt;/span&gt;&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.youtube.com/user/vProIntel"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;captured the secret tricks&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt; some San Franciscans use to pump life back into their under-the-weather PCs.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;I asked my buddy Dave Buchholz in Intel’s internal IT group if he had any low-tech fixes.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Dave’s title is IT Technology Evangelist.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;If his title conjures up the vision of someone perched atop an equipment cabinet with a tech manual cradled in one arm and soldering iron raised high in the other, well, that’s Dave.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;He’s an accomplished IT professional and something of an IT historian as well.&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Dave recalls years back that there was a period when the bearings in certain hard drives were typically the first thing to go.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;An audible clicking noise was the giveaway to the problem.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Dave says he’d put the ailing drives in a freezer where the bearings would contract slightly as they froze. &lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;Once back on a computer, the chilled drives would spin just long enough to offload the data.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Dave must have been working for a appliance company at the time because his fix for a gummed-up keyboard was to run it through a dishwasher.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Dave, this was a specialized IT dishwasher?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;I say &lt;em style="mso-bidi-font-style: normal;"&gt;low-tech&lt;/em&gt;, but when I asked readers to document their surefire fixes for getting their failed computers running again, solutions ranged from the spiritual (“shut down and restart and pray”) to "alchemy” (interestingly from an IT pro) with some tech solutions mixed in.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;In the interest of archiving the responses for businesses who may not yet have vPro or consumers interested in bettering their computer capabilities, I’ve taken a shot below at cataloging those I deem key for quick reference.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;I’ve placed them under appropriate tags that will make them easy to reference when the need arises.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;vPro, of course, makes it possible to diagnose and fix problems even in computers that are turned off, or have toasted operating systems or hard drives, and it’s capabilities are now reaching the small-business world with &lt;/span&gt;&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www3.intel.com/cd/channel/reseller/asmo-na/eng/products/desktop/platforms/itdirector_unmanaged/420331.htm?iid=SEARCH"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;Intel IT Director&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; and even &lt;/span&gt;&lt;/span&gt;&lt;a class="" href="http://communities.intel.com/community/openportit/vproexpert/emergingcomputing;jsessionid=A3DEEAB4596CE8D280770254C5E2D128"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;virtualized worlds&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;Nonetheless, not everyone has vPro.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt;For that reason, this undoubtedly will become a watershed resource.&lt;span style="mso-spacerun: yes;"&gt;  &lt;/span&gt;So, it’s important that it is complete and thoroughly thought through. &lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;If you want to propose a category to those below and add any solutions from the &lt;/span&gt;&lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/pressroom/archive/reference/Low-Tech_Survey_Results.pdf"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;complete list of fixes&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt; into it or suggest fixes of your own, now is the time to append them in the comments before catastrophe strikes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;My thanks along with the appreciation of those who may eventually need this resource to all of you who contributed.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;p align="center" class="MsoNormal" style="margin: 0in 0in 0pt; text-align: center;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;PC Fixes in Absence of Intel vPro Technology&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;KISS&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Turn it off and on&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Slightly Less Simple&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Ctrl+Alt+Del, then task manager and ending a whole bunch of tasks so only a few are left. If that doesn't work, restart the computer…after two minutes.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;KISS Plus&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Turning it off and then turning it back on again. Then hitting it really hard and see if something gets knocked loose.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Wisdom from IT Pros (Apparently from different schools, however)&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Extend the life of your computer - buy a desktop KVM and instead of chucking out the PC keep it as an internet-browsing "NetTop". Also useful for long-lasting downloads. Use the KVM to flick between your "main" PC and the NetTop&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Black tape. Or sometimes a good kick will do.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Confidential – Not To Be Shared with the IT Department&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Defrag, registration defrag and spyware removal&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Complete Emotional Breakdown&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Start crying, hit the delete button 1,000 times, and if all else fails call my sister and have her boyfriend save me from my tech catastrophe&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Tears - it must be the salt or maybe the computer gods taking pity on me but it seems to work&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Reboot, reboot, reboot!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Oxygen Depleted Environments&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Worst comes to worst, I always just take the battery out of my laptop and let it "breathe" a bit before plugging it back in and booting it up&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Try blowing air into any port - battery, power cord, usb port -- sometimes it actually works&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Call In the Marines&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Call my dad; he's some kind of a computer engineer&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Pick the Right Man&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Pawning it off on my boyfriend to fix!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Man Up and Do What Feels Right!&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;I've become very accustom to using hibernate and sleep modes. Why bother with a full shutdown and startup. But - IT support got a little upset…stating I was reckless, the system wasn't "made to do that", and so forth. So - back to the wasted time of shutdown and power-up&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;When Melt-Down (Structural or Emotional) Is Imminent&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Close my eyes and hope the problem goes away&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Call the geek squad – ask my children&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt; color: #000000;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong style="mso-bidi-font-weight: normal;"&gt;Don’t Even Mess with It, Refresh&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 0.25in;"&gt;&lt;span style="font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="color: #000000;"&gt;Accelerated upgrade cycle&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:7a641507-627b-4f90-8a3a-160fb631a8bb] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">manageability</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">client_management</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">virtualization</category>
      <pubDate>Tue, 28 Jul 2009 22:45:26 GMT</pubDate>
      <author>scott1.e.smith@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2009/07/28/ctrl-alt-delete-archiving-low-tech-computer-fixes</guid>
      <dc:date>2009-07-28T22:45:26Z</dc:date>
      <clearspace:dateToText>4 months, 2 days ago</clearspace:dateToText>
      <clearspace:replyCount>6</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/ctrl-alt-delete-archiving-low-tech-computer-fixes</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=12388</wfw:commentRss>
    </item>
    <item>
      <title>Microsoft OOB Console Requirement</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2009/06/08/microsoft-oob-console-requirement</link>
      <description>&lt;!-- [DocumentBodyStart:ddf82ee5-4ca7-4429-9003-dd0434a75302] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Hello vPro Experts!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I would like to pass on some information that I discovered a while ago, based on a Microsoft Premiere Support ticket. I was having trouble getting the Microsoft Out-of-Band (OOB) Management Console functioning from a Windows XP system. I tried everything on a fresh, standard build of Windows XP, but nothing would work.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;After working with Premiere Support, we finally discovered that Windows XP Service Pack 3 (SP3) was required for proper functioning of the Microsoft OOB console.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This behavior is actually related to some functionality that was &lt;span style="text-decoration: underline;"&gt;added&lt;/span&gt; in SP3, specifically in the &lt;em&gt;winhttp.dll&lt;/em&gt; library. There is a function called &lt;a class="jive-link-external-small" href="http://msdn.microsoft.com/en-us/library/aa384114(VS.85).aspx"&gt;WinHttpSetOption&lt;/a&gt; in the WinHttp library, which is called with a parameter enabling the &lt;a class="jive-link-external-small" href="http://msdn.microsoft.com/en-us/library/aa384066(VS.85).aspx"&gt;WinHttp Option Flag&lt;/a&gt; named &lt;em&gt;WINHTTP_ENABLE_SPN_SERVER_PORT&lt;/em&gt;. This flag enables the WinHttp library to include the server port in the Kerberos Service Principle Name (SPN), since the AMT web service is running on a non-standard HTTP port (16993).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The Windows XP Service Pack 2 (SP2) version of the WinHttp library does not include this capability, and consequently fails to authenticate. In order to properly connect to ConfigMgr-provisioned AMT devices with the Microsoft OOB Console, please make sure your helpdesk / support systems are running Windows XP SP3.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If you have any questions, feel free to post them in the comments section, and I will do my best to answer them. &lt;img height="16px" src="http://communities.intel.com/images/emoticons/happy.gif" width="16px"/&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trevor Sullivan&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Systems Engineer&lt;/em&gt;&lt;/p&gt;&lt;p&gt;OfficeMax Corporation&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:ddf82ee5-4ca7-4429-9003-dd0434a75302] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">oob</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">console</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">center</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">issue</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">failure</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">system</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">configuration</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">manager</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">microsoft</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">isv</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">configmgr</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">tools</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sccm_sp1</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">kerberos</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">trevor</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sullivan</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">problem</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sccm</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">authentication</category>
      <pubDate>Mon, 08 Jun 2009 17:24:06 GMT</pubDate>
      <author>pcgeek86@gmail.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2009/06/08/microsoft-oob-console-requirement</guid>
      <dc:date>2009-06-08T17:24:06Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/microsoft-oob-console-requirement</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=12247</wfw:commentRss>
    </item>
    <item>
      <title>Powershell: Exploring the Management Engine</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2009/02/24/powershell-exploring-the-management-engine</link>
      <description>&lt;!-- [DocumentBodyStart:4c2bb03d-245e-410d-ac99-fb5b036cf166] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Hello vPro Experts! &lt;img height="16px" src="http://communities.intel.com/images/emoticons/happy.gif" width="16px"/&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I would like to take some time to touch on exploration of the management engine via the local interface (specifically the HECI driver). In order to follow the exercise here, you'll need to have &lt;a class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Windows_PowerShell"&gt;Windows Powershell&lt;/a&gt; installed, have the &lt;a class="jive-link-external-small" href="http://www.intel.com/software/amt-dtk/"&gt;Intel AMT Developer Toolkit&lt;/a&gt; downloaded and installed, and have an AMT client (&lt;em&gt;does not need to be provisioned&lt;/em&gt;) with the HECI driver installed. The HECI driver should be downloadable from your OEM.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To give you a high-level idea of the program flow we'll use to access the AMT device, consider the following:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Load the "&lt;span style="color: #666699;"&gt;Manageability Stack.dll&lt;/span&gt;" .NET library&lt;/li&gt;&lt;li&gt;Create an instance of the &lt;span style="color: #666699;"&gt;ManageabilityStack.HeciWrapper&lt;/span&gt; object&lt;/li&gt;&lt;li&gt;Reference the properties and methods of the &lt;span style="color: #666699;"&gt;HeciWrapper&lt;/span&gt; object, and the &lt;span style="color: #666699;"&gt;HeciMeInfo&lt;/span&gt; object (provided by the &lt;span style="color: #666699;"&gt;HeciWrapper.MeInfo&lt;/span&gt; property)&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here is the Powershell code that correlates to the above process:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;Loading the .NET Library&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# Load the Manageability Stack .NET library&lt;/span&gt;&lt;/p&gt;&lt;p&gt;$AmtLib = "C:\Program Files\Intel\Manageability Developer Tool Kit\Manageability Stack.dll"&lt;br/&gt;[System.Reflection.Assembly]::LoadFile($AmtLib)&lt;br/&gt;&lt;span style="color: #339966;"&gt;# Create a HeciWrapper object&lt;/span&gt;&lt;/p&gt;&lt;p&gt;$Heci = New-Object ManageabilityStack.HeciWrapper&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# Pipe the $Heci variable into the Get-Member cmdlet to determine what properties&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# and methods are available to us.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;$Heci | Get-Member&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;Obtaining a list of embedded certificate hashes&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# List embedded certificate hashes&lt;/span&gt;&lt;br/&gt;$Heci.MeInfo.EnumerateHashHandles()&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;Getting the BIOS and AMT Versions&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# Retrieve the AMT version&lt;/span&gt;&lt;br/&gt;Write-Host "AMT version: $($Heci.Versions.Versions["AMT"])"&lt;br/&gt;&lt;span style="color: #339966;"&gt;# Retrieve the BIOS version&lt;/span&gt;&lt;br/&gt;Write-Host "BIOS version: $($Heci.Versions.BiosVersion)"&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 12pt;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;strong&gt;Retrieving Provisioning Information&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #339966;"&gt;# Retrieve the provisioning server name&lt;/span&gt;&lt;br/&gt;Write-Host "Provisioning server: $($Heci.MeInfo.GetAuditRecord().ProvServerFQDN)"&lt;br/&gt;&lt;span style="color: #339966;"&gt;# Determine provisioning date&lt;br/&gt;# This will return "01/01/0001 00:00:00" if not provisioned&lt;/span&gt;&lt;br/&gt;Write-Host "Provision date: $($Heci.MeInfo.GetAuditRecord().TlsStartTime)"&lt;br/&gt;&lt;span style="color: #339966;"&gt;# Get provisioning mode (Enterprise, SMB, etc.)&lt;/span&gt;&lt;br/&gt;Write-Host "Provision mode: $($Heci.MeInfo.GetProvisioningMode().ProvisioningMode)"&lt;br/&gt;&lt;span style="color: #339966;"&gt;# Get provisioning state&lt;/span&gt;&lt;br/&gt;Write-Host "Provision state: $($Heci.MeInfo.GetProvisioningState())"&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;-----------------------------------&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I hope these code samples are able to help you out in your administration / engineering endeavors! Please let me know if you have any questions, and don't forget that in Powershell .... when in doubt .... use &lt;span style="color: #808080;"&gt;Get-Member&lt;/span&gt; to discover what information is available to you!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Trevor Sullivan&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Systems Engineer&lt;/em&gt;&lt;/p&gt;&lt;p&gt;OfficeMax Corporation&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:4c2bb03d-245e-410d-ac99-fb5b036cf166] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">engineer</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">automate</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">deploy</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">microsoft</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">administration</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sullivan</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">tools</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">powershell</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">script</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">automation</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">trevor</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">manage</category>
      <pubDate>Wed, 25 Feb 2009 04:26:00 GMT</pubDate>
      <author>pcgeek86@gmail.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2009/02/24/powershell-exploring-the-management-engine</guid>
      <dc:date>2009-02-25T04:26:00Z</dc:date>
      <clearspace:dateToText>9 months, 6 days ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/powershell-exploring-the-management-engine</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11923</wfw:commentRss>
    </item>
    <item>
      <title>“Two days” in the life of an Intel® vPro Anti-Theft Technology for Asset Protection (AT-p) User</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2009/01/06/two-days-in-the-life-of-an-intel-vpro-anti-theft-technology-for-asset-protection-at-p-user</link>
      <description>&lt;!-- [DocumentBodyStart:e519a806-d8b2-4810-aa31-2e39c242a47a] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;span style="color: #000000;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The new generation of notebook PCs with Intel vPro technology includes Intel Anti-Theft Technology PC Protection (Intel AT-p). Intel AT-p offers you the option of activating hardware-based client-side intelligence to secure the PC and data if a notebook is lost or stolen. Because the technology is built into PC hardware, it provides local, tamper-resistant defense that works even if the OS is re-imaged, a new hard-drive is installed, or the notebook is not connected to the network.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;For a good introduction of the Intel® AT-p Technology please visit - &lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/vproexpert/blog/2008/12/04/anti-theft-technology-has-arrived"&gt;&lt;span style="color: #800080;"&gt;http://communities.intel.com/community/openportit/vproexpert/blog/2008/12/04/anti-theft-technology-has-arrived&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;In the following we describe an example of how this technology is deployed and used in the life of a typical employee working for a security conscious company. Consider a user Jane who is a new employee of a company called SecureBank. SecureBank wants all its employees laptops to be protected against theft and is therefore utilizing the &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/vproexpert/blog/2008/12/04/anti-theft-technology-has-arrived"&gt;&lt;span style="color: #800080;"&gt;Intel® vPro Anti-Theft Technology for Asset Protection (AT-p)&lt;/span&gt;&lt;/a&gt; with &lt;a class="jive-link-external-small" href="http://www.absolute.com/"&gt;Absolute ISV&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;In particular Jane has two (rather adventurous) days –&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 21pt; text-indent: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list 21.0pt;"&gt;&lt;span style="font-size: 11pt; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Times New Roman;"&gt;-&lt;span style="font-family: &amp;amp;quot;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;strong&gt;Day 1:&lt;/strong&gt;&lt;/span&gt; &lt;span style="font-size: 11pt; font-family: Calibri;"&gt;IT admin receives a new laptop and sets it up for Jane. Jane uses the new laptop for the day when she receives her new laptop and manages to loose it to a thief! &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 21pt; text-indent: -0.25in; mso-list: l2 level1 lfo2; tab-stops: list 21.0pt;"&gt;&lt;span style="font-size: 11pt; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Times New Roman;"&gt;-&lt;span style="font-family: &amp;amp;quot;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;strong&gt;Day 2:&lt;/strong&gt;&lt;/span&gt; &lt;span style="font-size: 11pt; font-family: Calibri;"&gt;the thief is unable to use the laptop due to the poison pill sent as a feature of the AT-p technology. The thief therefore gives up on it and leaves it in a coffee shop. The laptop is subsequently recovered by SecureBank, made functional again and is ready to be handed over to Jane.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Below are the details –&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;(Check out the video uploaded at youtube –&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;a class="jive-link-external-small" href="http://www.youtube.com/watch?v=bnTggBxhOVk&amp;amp;feature=email"&gt;http://www.youtube.com/watch?v=bnTggBxhOVk&amp;amp;feature=email&lt;/a&gt;)&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;Day 1:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;(1) Initial Setup by IT Admin:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The IT admin receives a new laptop and creates the SecureBank IT image on the laptop. This includes the Absolute agent which would be used for AT-p. The Absolute Client Windows Installer is a part of the IT image. The two key steps are undertaken -&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 21pt; text-indent: -0.25in; mso-list: l5 level1 lfo1; tab-stops: list 21.0pt;"&gt;&lt;span style="font-size: 11pt; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Times New Roman;"&gt;-&lt;span style="font-family: &amp;amp;quot;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;strong&gt;Enrollment:&lt;/strong&gt;&lt;/span&gt; &lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;The IT admin runs the Absolute Client Windows Installer which installs the Absolute agent on the client. As part of the installation this client is &lt;strong&gt;enrolled&lt;/strong&gt; with the Absolute server. Enrollment consists of the following steps –&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 57pt; text-indent: -0.25in; mso-list: l1 level2 lfo3; tab-stops: list 57.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;1.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The Absolute Agent checks the local platform to ensure that the platform is eligible for Intel® AT-p.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 57pt; text-indent: -0.25in; mso-list: l1 level2 lfo3; tab-stops: list 57.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;2.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The Agent requests permission of activate AT-p with the ISV Server i.e. the Absolute Server.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 57pt; text-indent: -0.25in; mso-list: l1 level2 lfo3; tab-stops: list 57.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;3.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The ISV Server takes this unique client request and sends it (along with a license key) to the Intel permit signing server. &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 57pt; text-indent: -0.25in; mso-list: l1 level2 lfo3; tab-stops: list 57.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;4.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Once the Intel signing server has validated this request, an AT-p permit is generated for that unique client. The client system is now ready to validate signed messages from the ISV server.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Once the machine is enrolled it shows up on the administrator console. The machine is identified using a unique identifier generated by the Absolute server, Detected Full Computer Name and Detected Serial Number. At this point a default policy for the client machine is also applied.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 21pt; text-indent: -0.25in; mso-list: l5 level1 lfo1; tab-stops: list 21.0pt;"&gt;&lt;span style="font-size: 11pt; mso-fareast-font-family: 'Times New Roman';"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;span style="font-family: Times New Roman;"&gt;-&lt;span style="font-family: &amp;amp;quot;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;strong&gt;Policy Setup:&lt;/strong&gt;&lt;/span&gt; &lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The IT admin can also fine tune the policy for Jane. Examples of Attributes he can set include:&lt;br style="mso-special-character: line-break;"/&gt;&lt;br style="mso-special-character: line-break;"/&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="border-collapse: collapse; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 480; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext;"&gt;&lt;tbody&gt;&lt;tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"&gt;&lt;td style="padding-right: 5.4pt; padding-left: 5.4pt; background: navy; padding-bottom: 0in; width: 1.45in; padding-top: 0in; mso-border-alt: solid windowtext .5pt; border: windowtext 1pt solid;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; color: #ffffff; font-family: Calibri;"&gt;Policy Attribute&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; background: navy; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; color: #ffffff; font-family: Calibri;"&gt;Example Value&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; background: navy; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; color: #ffffff; font-family: Calibri;"&gt;Meaning&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 1;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;AT-p Timer Value&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;48 hours&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The machine’s disablement timer (time after which the machine is disabled if it does not connect with the server) is 48 hours.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 2;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;AT-p Timer Action&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Immediate Lock&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The action a machine performs once the AT-p Timer has expired. In this case, the machine will shut down immediately (even if OS was up and running) and not allow the boot process to be carried out.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 3;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;AT-p Theft Action&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Immediate Lock&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The action a machine performs once the machine is marked stolen when connecting with the server. In this case, the machine will shut down immediately, same as above.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 4;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;AT-p Password&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;“StRongP@ssw0rd”&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Admin Password used to recover the machine when it is disabled or locked.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 5;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;AT-p&lt;/strong&gt;&lt;strong&gt;State&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Active&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Marks whether AT-p is currently active or not on a machine. When it has a legitimate working user then it is marked as active.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 6; mso-yfti-lastrow: yes;"&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 1.45in; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="139"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;strong&gt;Theft Status&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 103.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="138"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Secure&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 234.9pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt;" valign="top" width="313"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Marks whether the machine is stolen or secure. In this case, the machine is not stolen.&lt;/span&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;br/&gt;&lt;br/&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Once the IT admin has set the above policy he is ready to hand over the laptop to Jane.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;(2) Normal Usage:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;On receiving her new Laptop, Jane logs in with her domain credentials and uses it seamlessly (as if there were no AT-p). The rendezvous may occur without any active participation of Jane. As such the rendezvous happens in the background and is transparent to Jane. &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;- Rendezvous (Machine Not Stolen)&lt;br/&gt;&lt;/strong&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The Absolute solution has a rendezvous timer of 24.5 hours. After this time the following steps would occur –&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 39pt; text-indent: -0.25in; mso-list: l3 level1 lfo4; tab-stops: list 39.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;1.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;As the Rendezvous Timer (24.5 hours) expires the ISV Client Agent initializes a rendezvous.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 39pt; text-indent: -0.25in; mso-list: l3 level1 lfo4; tab-stops: list 39.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;2.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The ISV Server’s response is relayed to the Intel Management Engine (in the firmware) through the ISV Client Agent. Any new settings are relayed.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 39pt; text-indent: -0.25in; mso-list: l3 level1 lfo4; tab-stops: list 39.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;3.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Acknowledgments are generated for any message received.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 39pt; text-indent: -0.25in; mso-list: l3 level1 lfo4; tab-stops: list 39.0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri; mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;4.&lt;span style="font-family: &amp;amp;quot;"&gt;     &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;span dir="ltr"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Once finished, the Disablement Timer (or AT-p Timer) reset message is sent to the Intel Management Engine.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;(3) Theft:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;After a good first day of work, Jane’s colleagues take her out for a dinner. She leaves her laptop in the car and heads to the restaurant. To Jane’s bad luck her car is broken into and the notorious thief steals her laptop.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;- &lt;strong&gt;Malicious Usage:&lt;/strong&gt; The thief has a hacking tool that allows bypassing the windows login/password challenge and can use the laptop. He feels he can make a good fortune by selling this laptop in the black-market.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;- &lt;strong&gt;Theft Reporting:&lt;/strong&gt; When Jane returns to the car, she is shocked to see her car broken into and her laptop stolen. She immediately calls the IT admin helpdesk and reports the theft. &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt; The IT admin sets the &lt;strong&gt;Theft Status&lt;/strong&gt; to Stolen. Next time the laptop checks in with the Absolute server, the &lt;strong&gt;Theft Action, which&lt;/strong&gt; is Immediate Lock, will take place.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;Day 2:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;(4) Poison Pill:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The attacker logs in again using his hacking tool. &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;Since it is past 24.5 hours (i.e. the rendezvous timer has expired) the agent initiates a rendezvous. At this time the following steps happen -&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;- &lt;strong&gt;Rendezvous (Machine Stolen)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo5; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;As the rendezvous timer expires the ISV Client Agent initializes a rendezvous.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo5; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The server has marked the system as stolen, and sends an &lt;strong&gt;&lt;span style="color: #666699;"&gt;AssertStolen&lt;/span&gt;&lt;/strong&gt; message (“Poison Pill”) to the system.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l0 level1 lfo5; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The local system takes action based on the current policy.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;As the action is to immediately lock, the thief to his surprise observes that the machine just shuts down. When he tries to power on the machine he sees a pre-boot authentication screen which requests him to insert admin credentials. The thief’s hacker tools are not able to bypass this screen as the same OS (which is potentially more vulnerable) as the pre-boot environment serves as an extension of the boot firmware and guarantees a secure, tamper-proof environment external to the operating system as a trusted authentication layer. Brute force attacks in this environment are also much harder as the tamperproof firmware reboots the machine after a threshold time or number of attempts to login has expired.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;To the thief’s dismay, he cannot really use the laptop and leaves it in the coffee shop where he logged in from.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;strong&gt;(5) Asset Recovery:&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The IT admin of SecureBank was able to get the IP of the location where the thief last logged in from and contacts the coffee shop. SecureBank officials pick up the laptop and bring it back to the IT admin desk for recovery. To recover the platform the IT admin carries out the following steps –&lt;/span&gt;&lt;/p&gt;&lt;ol start="1" style="margin-top: 0in;" type="1"&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo6; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The IT admin (re)sets the &lt;strong&gt;&lt;span style="color: #666699;"&gt;Theft Status&lt;/span&gt;&lt;/strong&gt; to be Secure (from Stolen).&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo6; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Upon boot, the admin is presented with a “system locked” message in the pre-boot environment.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo6; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;The admin recovery passphrase must be entered before a given time (say 2 minutes). &lt;span style="mso-spacerun: yes;"&gt;&lt;/span&gt;The admin immediately inputs his admin passphrase for the given machine.&lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin: 0in 0in 0pt; mso-list: l4 level1 lfo6; tab-stops: list .5in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;When the admin credentials and theft status have been verified, the AT-p timer is reset and the client platform is unlocked. The platform then boots to the OS.&lt;span style="mso-spacerun: yes;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;Once this is done, the IT admin is ready to return this machine back to Jane without loosing any time. Thus we can see that AT-p solution not only provides a way to secure machines against theft and continued malicious use, but also ensures efficient recovery and continued use of the recovered machine!&lt;/span&gt;&lt;/p&gt;&lt;div style="border-right: medium none; padding-right: 0in; border-top: medium none; padding-left: 0in; padding-bottom: 1pt; margin-left: 3pt; border-left: medium none; margin-right: 0in; padding-top: 0in; border-bottom: windowtext 1pt solid; mso-element: para-border-div; mso-border-bottom-alt: solid windowtext .75pt;"&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt; mso-padding-alt: 0in 0in 1.0pt 0in; mso-border-bottom-alt: solid windowtext .75pt; padding: 0in;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;p class="MsoNormal" style="margin: 0in 0in 0pt 3pt;"&gt;&lt;span style="font-size: 11pt; font-family: Calibri;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:e519a806-d8b2-4810-aa31-2e39c242a47a] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro_anti-theft_technology</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">case_study</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro_expert_center</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">absolue</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">asset_protection</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">tools</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">intel_vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">at-p</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <pubDate>Tue, 06 Jan 2009 23:28:26 GMT</pubDate>
      <author>abhilasha.bhargav-spantzel@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2009/01/06/two-days-in-the-life-of-an-intel-vpro-anti-theft-technology-for-asset-protection-at-p-user</guid>
      <dc:date>2009-01-06T23:28:26Z</dc:date>
      <clearspace:dateToText>10 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/two-days-in-the-life-of-an-intel-vpro-anti-theft-technology-for-asset-protection-at-p-user</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11806</wfw:commentRss>
    </item>
    <item>
      <title>AMT 4.0 (vPro 2008)  -  New Icon for Management &amp; Security Status</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/04/amt-40-vpro-2008-new-icon-for-management-security-status</link>
      <description>&lt;!-- [DocumentBodyStart:2f8f2477-98b2-47a1-a931-3892c6369eea] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Here's a followon post for the new ICON in the system tray. I just received my new Dell e6400 machine and thought showing the real icon vs. the screen shots from the past would be helpful.  They definitely show more information as I discussed prior.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;a class="jive-link-blog-small" href="http://communities.intel.com/community/openportit/vproexpert/blog/2008/09/11/centrino2-with-vpro-finally-more-screens-to-share-out"&gt;Centrino2 with vPro  - Finally more Screens to share out&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;!--[CodeBlockStart:b6e56d04-655a-468c-b490-78c6f1875c76]--&gt;&lt;span&gt;&lt;embed allowfullscreen="true" allowscriptaccess="always" height="344" src="http://www.youtube.com/v/2bF6PJZ4f2Y&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" width="425"&gt;&lt;/embed&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:b6e56d04-655a-468c-b490-78c6f1875c76]--&gt;&lt;!--[CodeBlockStart:457b15e2-da3e-44e3-ac17-706ddd2d414b]--&gt;&lt;span&gt;&lt;br/&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:457b15e2-da3e-44e3-ac17-706ddd2d414b]--&gt;&lt;!--[CodeBlockStart:bb933e7a-c79f-4d09-9a37-bb23f6fb968f]--&gt;&lt;span&gt;&lt;br/&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:bb933e7a-c79f-4d09-9a37-bb23f6fb968f]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Quick Tip for the Dell e6400&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;During bootup you will NOT be presented with a CTRL+P screen, however if you hit right after the machine starts it will take you into the MEBx.   I looked throughout the BIOS and there are no places to change this. if you find a route, let me know.. &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Josh H&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:2f8f2477-98b2-47a1-a931-3892c6369eea] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro_expert_center</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">josh_hilliker</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">video</category>
      <pubDate>Tue, 04 Nov 2008 18:51:19 GMT</pubDate>
      <author>josh.hilliker@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/04/amt-40-vpro-2008-new-icon-for-management-security-status</guid>
      <dc:date>2008-11-04T18:51:19Z</dc:date>
      <clearspace:dateToText>1 year, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/amt-40-vpro-2008-new-icon-for-management-security-status</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11682</wfw:commentRss>
    </item>
    <item>
      <title>Simple &amp; easy way to validate machine state with PING</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/04/simple-easy-way-to-validate-machine-state-with-ping</link>
      <description>&lt;!-- [DocumentBodyStart:f44fc23a-2966-43f5-9103-13cd6d7be4f3] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Here's a TIP from our Interop team around how to verify whether a ping response is through OS or ME.  To do so you look to the TTL field in teh ping response.  &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;value in the range of 127/128 = OS NIC responding&lt;/p&gt;&lt;p&gt;Value in the range greater &amp;gt; 128 = ME is responding&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here's a quick video. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;!--[CodeBlockStart:874f7272-2652-480c-8e37-b54dd9fd715b]--&gt;&lt;span&gt;&lt;embed allowfullscreen="true" allowscriptaccess="always" height="344" src="http://www.youtube.com/v/lSFFepy3APU&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" width="425"&gt;&lt;/embed&gt;&lt;/span&gt;&lt;!--[CodeBlockEnd:874f7272-2652-480c-8e37-b54dd9fd715b]--&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f44fc23a-2966-43f5-9103-13cd6d7be4f3] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro_expert_center</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">josh_hilliker</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">video</category>
      <pubDate>Tue, 04 Nov 2008 18:03:07 GMT</pubDate>
      <author>josh.hilliker@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/11/04/simple-easy-way-to-validate-machine-state-with-ping</guid>
      <dc:date>2008-11-04T18:03:07Z</dc:date>
      <clearspace:dateToText>1 year, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/simple-easy-way-to-validate-machine-state-with-ping</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11680</wfw:commentRss>
    </item>
    <item>
      <title>New stuff in Known Issues/Best Practices wiki: SCS, Intel AMT Status dialog, LANDesk, SCCM</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/07/30/new-stuff-in-known-issuesbest-practices-wiki-scs-intel-amt-status-dialog-landesk-sccm</link>
      <description>&lt;!-- [DocumentBodyStart:6b0df7a9-e992-4da2-874e-05d0899980fd] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Check out the new articles this week!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ISV_SCCM2"&gt;Virtual adapters may cause network discovery to fail&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ISV_SCCM1"&gt;Enabling native (no translation required) support within Microsoft SCCM SP1&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SCS19"&gt;Time synchronization errors using Intel®(R) SCS 3.x and Active Directory&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SCS20"&gt;SCS Installation Account Security Requirements&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ISV_L1"&gt;No drivers required for bare metal provisioning (LANDesk)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#BP3"&gt;Customizing the Intel AMT Status dialog box&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:6b0df7a9-e992-4da2-874e-05d0899980fd] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">best-practices</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sccm_sp1</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">landesk</category>
      <pubDate>Wed, 30 Jul 2008 23:12:44 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/07/30/new-stuff-in-known-issuesbest-practices-wiki-scs-intel-amt-status-dialog-landesk-sccm</guid>
      <dc:date>2008-07-30T23:12:44Z</dc:date>
      <clearspace:dateToText>1 year, 4 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/new-stuff-in-known-issuesbest-practices-wiki-scs-intel-amt-status-dialog-landesk-sccm</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11392</wfw:commentRss>
    </item>
    <item>
      <title>New - Troubleshooting &amp; Best Practices - 5 new articles posted!</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/06/13/new-troubleshooting-best-practices-5-new-articles-posted</link>
      <description>&lt;!-- [DocumentBodyStart:c14a8d34-75cd-48a3-bc9a-24a408bd8b43] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;New content was just published to the  &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Known Issues, Best Practices, and Workarounds&lt;/a&gt;. Check'em out!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ME10"&gt;Does Intel AMT 3.0 support Windows 2000 Active Directory?&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#BP2"&gt;Changing Terminal Emulation Type&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SCS16"&gt;SOAP error (0xCFFF06AC) when attempting remote configuration&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ME9"&gt;Network issues with NS Lookup&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#ME8"&gt;Best Practices: Setting up application servers and Internet Explorer* for Intel(R) AMT Kerberos support&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:c14a8d34-75cd-48a3-bc9a-24a408bd8b43] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">active_directory</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">kerberos</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">best-practices</category>
      <pubDate>Fri, 13 Jun 2008 21:05:29 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/06/13/new-troubleshooting-best-practices-5-new-articles-posted</guid>
      <dc:date>2008-06-13T21:05:29Z</dc:date>
      <clearspace:dateToText>1 year, 5 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/new-troubleshooting-best-practices-5-new-articles-posted</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11276</wfw:commentRss>
    </item>
    <item>
      <title>My top 3 tool picks for starting to use vPro</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/29/my-top-3-tool-picks-for-starting-to-use-vpro</link>
      <description>&lt;!-- [DocumentBodyStart:d39e9b2f-ce23-47d1-861f-eb1bb5d26d3b] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;I wanted to share out why my top 3 tool picks are for starting up with vPro, usually I am using these tools when I'm working on connectivity, packets or errors in the logs in the mgmt console. I also often find that I'm using these tools late at night when i'm deep in troubleshooting mode &amp;amp; trying to do a root cause on why something is not working as planned i.e. hello packets are not starting on a given hardware platform, etc..   (I'll save the showcase for a youtube video soon).. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;here they are.................   &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;#1.  MEinfowin.exe&lt;/strong&gt; -  Brian C posted a good link of where &amp;amp; how to get this from Lenovo's BIOS update.   I highly recommend this tool for troubleshooting version of the ME, SOL, etc..  it also has good information on setup &amp;amp; configuration, link status, etc.. &lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://communities.intel.com/message/3649#3649"&gt;http://communities.intel.com/message/3649#3649&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;#2.  Wireshark&lt;/strong&gt;&lt;span&gt; - Joel Smith (altiris) wrote about this in his blog, which is where I initially found the link.  &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/3636/troubleshooting-altiris-manageability-toolkit-vpro-technology-part-1-provisioning-clien"&gt;http://juice.altiris.com/article/3636/troubleshooting-altiris-manageability-toolkit-vpro-technology-part-1-provisioning-clien&lt;/a&gt;&lt;span&gt;  &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://www.wireshark.org/"&gt;Wireshark&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;While the two above tools are distinctly for Out of Band Provisioning, Wireshark tells the whole story of what is coming and going across the wire. It's important to know what the AMT clients are sending, especially in the 'Hello' packet, and what the server is responding with.&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;span&gt;Wireshark can be obtained from: &lt;/span&gt;&lt;a class="jive-link-external-small" href="http://www.wireshark.org/"&gt;http://www.wireshark.org/&lt;/a&gt;&lt;span&gt;. While this is the recommended tool, any network trace capture program can be used to examine the network traffic between the AMT client and the Provisioning Server.&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;#3.  Intel® vPro™ Technology Test Utility&lt;/strong&gt; - this is the old faithful tool to ensure your vPro system has the right ingredients.  &lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-external-small" href="http://downloadcenter.intel.com/Product_Filter.aspx?ProductID=2575"&gt;http://downloadcenter.intel.com/Product_Filter.aspx?ProductID=2575&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;These are my top 3, however if I were to go, in SMB mode I utilize the vPro Packet decoder and the AMT reflector, however I use those at very specific times when i've passed the top 3 and I am digging in even deeper. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I hope you enjoy the list and if you have a TOP tool favorite write a comment at the end of the blog and let me know as I am always looking for new tools that help troubleshooting. &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Josh H&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:d39e9b2f-ce23-47d1-861f-eb1bb5d26d3b] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">tools</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">josh_hilliker</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro_expert_center</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">manageability</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <pubDate>Fri, 30 May 2008 05:42:32 GMT</pubDate>
      <author>josh.hilliker@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/29/my-top-3-tool-picks-for-starting-to-use-vpro</guid>
      <dc:date>2008-05-30T05:42:32Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/my-top-3-tool-picks-for-starting-to-use-vpro</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11234</wfw:commentRss>
    </item>
    <item>
      <title>Handling vPro AMT FQDN issues with Out of Band Management Solution</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/15/handling-vpro-amt-fqdn-issues-with-out-of-band-management-solution</link>
      <description>&lt;!-- [DocumentBodyStart:f269f33c-0913-4826-b009-22f55ab19256] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The primary key of identity for an AMT computer is its Fully Qualified Domain Name (FQDN). One of the essential parts of the setup and configuration process (Provisioning) is when Altiris attempts to map a valid FQDN inside the IntelAMT database. This article covers how to handle FQDN issues, including ways to correct invalid entries, the best method to avoid the issues, and how it all works. If you're using Altiris Out of Band Management for provisioning, this is a must read!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;The two key identity items for vPro are the UUID (Universally unique Identification) and the FQDN. The UUID is contained within the hello packet sent by AMT, but the FQDN is not held within AMT without Provisioning. This means it is up to Altiris to acquire the system's FQDN. While this may sound simple, the problems arise when the system is in its setup process, whether prepping or being imaged, having software and scripts rolled out to provision and join the system to the domain, including when its final identity on the Domain and network are established and it received a new IP Address.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Preferred Provisioning method&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;For specifics I'll refer to the Best Practices document, but for the general steps to be followed specifically for the FQDN I'll provide the steps below.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;LINK: &lt;a class="jive-link-external-small" href="http://juice.altiris.com/article/2810/best-practices-configuring-intel-vpro-capable-system-within-symantecaltiris-vpro-toolki"&gt;http://juice.altiris.com/article/2810/best-practices-configuring-intel-vpro-capable-system-within-symantecaltiris-vpro-toolki&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Image the system with the Operating System, including any post-imaging work to get the system configured. This includes rolling out software or scripts.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Join the system to the Domain after it has its rightful identity. The computer name should be set. When the computer is joined to the domain, this will provide the valid operable FQDN.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Install the Altiris Agent on the system. This provides the information for the FQDN in the Inv_AeX_AC_Location table. &lt;br/&gt;+NOTE: If the Altiris Agent was part of the image, make sure the system sends Basic Inventory again after the system has been joined to the network to ensure we have the valid FQDN within the Altiris database.+&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Ensure the Out of Band Discovery package is enabled and configured via the collection to go to all machines. &lt;br/&gt;+NOTE: This step is essential because OOB Discovery will pick up the FQDN from the Basic Inventory and map it in the IntelAMT database. This screenshot shows where the data is located:+ &lt;br/&gt;+!OOBCapACLocation.JPG!+&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Now if the hello message was sent before the above steps were completed, normally it will recover as long as the process completes before 24 hours have passed. 24 hours is the period of time the hello packets will be sent from the client. AMT will continue to send hello packets throughout the period UNTIL it is fully provisioned. This helps reestablish connection if the IP Address changes in the middle of the Provisioning process and the Server can't connect back up to the remote AMT system.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Preferred Provisioning Settings&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Not all settings within Out of Band are FQDN friendly. The following items affect how Out of Band Management approaches provisioning.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;Resource Synchronization&lt;/strong&gt; - Make certain this is enabled! A Disabled Resource Synch policy will halt Provisioning, greatly increasing the change for FQDN problems when it is finally enabled.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;Use DNS IP resolution to find FQDN when assigning profiles&lt;/strong&gt; - This option, under the Resource Synchronization policy, is typically unreliable. While this option allows for bare-metal provisioning or Agentless provisioning, it also is at the mercy of the DNS and DHCP environment. It is highly recommended &lt;strong&gt;NOT&lt;/strong&gt; to use this option unless you fully trust your DHCP and DNS environment. Factors to consider are:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;IP Lease times - The lease times afforded systems may be short, increasing the possibility that when OOB fetches the FQDN via IP the lease will have expired and the wrong FQDN will be mapped.&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;PXE or other auxiliary boots - Often these types of systems will obtain a different IP address from DHCP as their identity is not the same as when the system is booted to the OS. &lt;br/&gt;!ResourceSynchronizationOOB2.JPG!&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;Intel AMT 2.0+ to Profile&lt;/strong&gt; - This option allows a default Profile to be setup for Provisioning. Make sure you've created a default profile and set it in the Resource Synchronization policy. Without a profile Provisioning will not occur.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;Intel AMT requires authorization before provisioning&lt;/strong&gt; - Under the General node within Provisioning, this option stops provisioning from occurring. The profile will not go down to the system until the system is selected, using the right-click to choose ‘authorize'. This can aggravate FQDN problems by delaying full provisioning.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;FQDN Fixes&lt;/span&gt;&lt;/h1&gt;&lt;h2&gt;&lt;span&gt;Invalid FQDN in IntelAMT&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The first issue stems from a variety of causes. The issue is that in the IntelAMT database, shown under the Intel AMT Systems node under Provisioning for Out of Band Management, the FQDN is invalid. The causes vary, but here are a few we've seen:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;Reverse DNS IP Lookup is enabled&lt;/strong&gt; - Unless your DHCP and DNS environment are rock solid, often IP Address leases expire, and other systems pick up the IPs that the AMT systems originally sent the Hello message with. When this occurs, the wrong FQDN is mapped.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;IP Leases short&lt;/strong&gt; - Often the IP Lease length can create a problem acquiring the correct FQDN. This can especially have problems with TLS as the FQDN is part of authentication using certificates.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;&lt;strong&gt;FQDN is incomplete&lt;/strong&gt; - When a system is in setup mode, sometimes the mapped FQDN is not part of a domain, resulting in the Host Name only being set as the FQDN.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;IMPORTANT!&lt;/strong&gt; When the FQDN is invalid in the IntelAMT database, Resource Synchronization can have troubles matching resources with their correct counterparts in the Altiris database. Because of this, duplicates can emerge. If the checkbox in Resource Synchronization labeled: ‘Remove duplicate Intel AMT resources from Notification Server database' is checked, managed resources can get deleted from the Altiris database!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;FQDN has Changed&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Another not-uncommon occurrence is when a system changes identity. This can occur in a variety of ways, including:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The system has been reimaged&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The computer name has been changed&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The computer has been migrated to a new Domain&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The system has switched subnets, resulting in a new FQDN&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Regardless of the method, changing the FQDN on the system does not change it in the Intel ME or AMT firmware, and also does not change it within the Intel SCS component database (IntelAMT). When these are not synched up, it can cause problems when you need to manage the system via AMT when the computer is booted to the operating system. This particularly has problems when TLS is enabled and the provisioned certificate no longer matches the FQDN in Windows.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Issues Resolution&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Since the Altiris Agent sends Basic Inventory daily by default, the Altiris database usually has a valid FQDN on record in the Inv_AeX_AC_location database table. We can run a query that will capture the correct FQDN from the Altiris database and insert it into the IntelAMT database, correcting any duplicate or invalid FQDN entries. This is the first step. The second step is to update the FQDN within AMT on the local systems. The following processes walk you through the resolution:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;&lt;span&gt;Update IntelAMT from Altiris&lt;/span&gt;&lt;/h3&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Open up SQL Query Analyzer or Microsoft SQL Server Management Studio.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Open a Query window within the database instance that contains both the Altiris database and the IntelAMT database.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Run the following query, though for testing purposes you can omit the line ‘COMMIT TRANSACTION until you can verify the operation completed as expected. Once validated, run COMMIT TRANSACTION to complete the process: &lt;br/&gt;	BEGIN TRANSACTION &lt;br/&gt;	UPDATE intelamt.dbo.csti_amts SET fqdn = b.fqdn FROM (SELECT il.[Fully Qualified domain name] AS 'fqdn', &lt;br/&gt;	REPLACE(oob.uuid, '-', '') AS 'uuid' FROM &lt;br/&gt;	altiris.dbo.Inv_AeX_AC_Location il JOIN altiris.dbo.Inv_OOB_Capability oob ON &lt;br/&gt;	oob._ResourceGuid = il._Resourceguid) b WHERE intelamt.dbo.csti_amts.uuid = b.uuid &lt;br/&gt;	COMMIT TRANSACTION&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Done! The FQDNs now match between Altiris and IntelAMT.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h3&gt;&lt;span&gt;Update FQDN on local AMT&lt;/span&gt;&lt;/h3&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;It is recommended to follow these steps in batches so as to not overwhelm the Intel SCS component. Perhaps run this against 100 systems at any one time, or run it against those systems you know have been updated. While it doesn't hurt to run this against systems that didn't have the FQDN changed from the above process, it is unnecessary if you are able to target those systems with invalid FQDNs. &lt;br/&gt;+Note: This process assumes that the system can be reached via the SCS using the new FQDN supplied by Altiris. For TLS there may be complications we have not foreseen.+&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In the Altiris Console browse under View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Intel AMT Systems &amp;amp;gt; and select the Intel AMT Systems node.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Select one or more systems you need to update the local AMT FQDN on.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Right-click and choose the ‘Re-provision...' option. &lt;br/&gt;!Re-provision.JPG!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Check the Action status node under Provisioning &amp;amp;gt; Logs &amp;amp;gt; Action Status for messages concerning the Re-provision attempts. You can also check the Log node for errors.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Done! The systems, when reprovisioned, should have the correct FQDN planted by the IntelAMT database entry that was updated from the Altiris database.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Use this article to resolve your FQDN issues to ensure ATM functionality is available when it is needed. The above process has been verified, though all environmental potential issues have not been explored. It is advised to test the process in your environment before implementing on a wide scale.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f269f33c-0913-4826-b009-22f55ab19256] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">centrino_pro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">fqdn</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">symantec</category>
      <pubDate>Thu, 15 May 2008 20:35:07 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/15/handling-vpro-amt-fqdn-issues-with-out-of-band-management-solution</guid>
      <dc:date>2008-05-15T20:35:07Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/handling-vpro-amt-fqdn-issues-with-out-of-band-management-solution</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11169</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 7 - Task Server</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/08/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-7-task-server</link>
      <description>&lt;!-- [DocumentBodyStart:5fde44d3-a078-42bd-9f40-3a8520ea1b29] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The Task Server contains AMT function tasks that give you the ability to integrate AMT functionality into Task Server Jobs. This allows you to use AMT in conjunction with Software Delivery, Scripting, and any other Task Server supported function. Understanding how to troubleshoot the AMT side of a Task Server job will help resolve issues so that AMT can be utilized. This includes the following technologies:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;System Defense - Network Filtering&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Reliable Power Management&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;IDE redirect for boot redirection&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This is the concluding article for the series: Troubleshooting the Altiris Manageability Toolkit for vPro Technology. The first four articles covered the setup and configuration of AMT systems, while parts 5 and 6 covered RTCI and RTSM respectively. This final article discusses troubleshooting the AMT integration into Task Server when issues arise.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As an introduction, the actual SOAP or API calls made to the AMT system is invoked through Real-Time Console Infrastructure, the same as when they are invoked through the Real-Time tab for RTSM. Though the calls are from the same place, how those calls are made differ. The following subjects will be covered:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Determining Cause of Failure&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;AMT Detection Issues&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Authentication Issues&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Determining Cause of Failure&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Often you'll known the general symptom that tells you a job or task in Task Server didn't execute as expected. For example a power management task may have shown as run but the AMT system never woke up. A failure is not shown except deep within a series of status windows.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To determine the returned error, use the following steps. Task Server's actual failure code is buried deep in a series of status windows, as shown in the screenshot after the steps.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the Task or Job that failed, double-click on the general status row for the specific execution attempt.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If within a job, double-click on the line that represents the task or AMT function that failed.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Note the numbers of successes versus failures. Click the ‘View Report' link.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Now you'll get a grid with the status of the Task, including the status and return code, if present.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-11147-1387/TaskServerStatusWindows.jpg"&gt;&lt;img height="369" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-11147-1387/620-369/TaskServerStatusWindows.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;AMT Detection Issues&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;When Task Server reaches a Task that involves AMT, it makes direct calls to AMT in those systems targeted in the task or job. Detecting AMT and subsequently executing the scheduled function requires success at both junctures. The following sections discuss potential issues and solutions in this process.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Power State Unknown&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;One common problem we see is when a power management task fails due to the failure message: Generic error, FromState detected as unknown:14. This will cause the power action to fail. The causes vary, but the following list contains the most common:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;System unreachable - The target system is not available on the network&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;AMT failed to be detected - See the subsequent section ‘AMT not detected'&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Authentication failed - See the subsequent section ‘Authentication Troubleshooting'&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;AMT is unavailable - If a system is not provisioned, or AMT is not functioning on that system&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Use the following process to determine what the issue is:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If RTSM is available, try connecting to the target system using RTSM, specifying the same credential profile.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If that fails, try manually putting in credentials until you find one that works.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If Step 1 succeeds, try creating a different connection profile with only AMT functions provided.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If no RTSM is available, still try the profile with only AMT functions to see if it works.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Try other AMT functions, such as Collect Intel AMT Inventory to see if they succeed.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If other functions succeed, try using another method to reboot the system to reset the power state stored in the Intel ME. One way to accomplish this is using the Task Server Power Management Agent to send down a standard reboot command to the PC.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If no other AMT functions are successful, AMT might not be properly setup on this system. Ask the question: Has this system gone through the provisioning process?&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If unknown, use the Out of Band Discovery Task to see if AMT is available and to identify what state it is in. See the steps provided under the ‘AMT Not Detected' section following.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If all else fails (generally this is on a system-by-system basis, rarely do a collection of systems encounter this level of this issue) try reprovisioning the system by fully unprovisioning and going through the provisioning process again.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;AMT Not Detected&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Normally a non-vPro system will receive the return code that AMT was not detected. This is accurate, but when it happens to valid managed vPro systems, the issue must be troubleshot to determine why the applying Task Server cannot detect AMT on the system. Out of Band Discovery is a great way to determine what state the system is in. Use the following steps to take stock of the systems:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In the Altiris Console, browse to View &amp;amp;gt; Solutions &amp;amp;gt; Out of Band Management &amp;amp;gt; Configuration &amp;amp;gt; Out of Band Discovery &amp;amp;gt; and select the ‘Out of Band Discovery' policy.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Enable the policy if it is not yet enabled. If it is enabled, set a schedule to run the discovery again so you have updated information on your systems.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;On the AMT system in question, go to the Altiris Agent and bring up the Agent UI by double-clicking on the system tray icon or by launching C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Highlight the ‘Out of Band Discovery Package.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click the ‘Out of Band Discovery' link under Application Tasks. &lt;br/&gt;!OOBDiscoveryRun.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once completed, now check back at the server and double-click the system within a collection to bring up Resource Manager.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Click on the Inventory tab and browse to Out of Band Management, and select the data class OOB Capability. This will give you the details of AMT.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If AMT is disabled, it needs to be enabled in the BIOS. A BIOS update from the vendor may provide you a remote way to enable AMT, by using Software Delivery for example. If it is all enabled, next check the provisioning status. Provision as necessary.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Authentication Issues&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;As with RTSM, Task Server uses the same basic authentication method when executing against a computer. Task Server also includes another option to add additional credentials to the execution to be used when contacting the protocol, which is AMT in this case.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Authentication Methods&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;Since RTCI controls the authentication, much of the same method is used whether the execution of an AMT command is issues from the Real-Time console or from Task Server, however there are some differences.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Runtime Profile&lt;/strong&gt; - The Runtime profile contains he following information:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;All known good credentials used to connect via RTSM to a system&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The Intel SCS AMT password sent to systems when provisioning occurs&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Previously successfully used credentials from past RTSM sessions&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Previously successfully used credentials from a Task that succeeded&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;User-defined Profiles&lt;/strong&gt; - Profiles can be created that specifically provide credentials for the four types of technologies:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;WMI digest or Domain account&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;AMT digest or Kerberos-authenticated user&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;ASF digest or Domain account&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;SNMP community strings&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Task-specified Credentials&lt;/strong&gt; - When a user setups up a job or task, the user can specify specific credentials to be used when executing AMT-related functions through the profile interface. This option is per job or task, and applies to all AMT functions invoked during the job or task. The Interface allows this as shown in the following screenshot:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-11147-1388/Task-newprofile.jpg"&gt;&lt;img height="436" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-11147-1388/620-436/Task-newprofile.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Authentication Troubleshooting&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The following method will help identify issues and offer ways to work-around and solutions. These have been compiled through experience when troubleshooting issues with failed authentication with Task Server.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;First, how do you determine if your task or job is failing due to authentication? Use the previous section under Introduction labeled ‘Determining Cause of Failure'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In the Altiris Console browse to View &amp;amp;gt; Solutions &amp;amp;gt; Real-Time Console Infrastructure &amp;amp;gt; Configuration &amp;amp;gt; select Manage Credentials Profiles, or in the Task click the ‘Run Now', and on the subsequent page click on the pencil icon next to the credential profile being used.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Where does the green checkmark fall? This is the default profile that will be used when connecting via a Task Server task.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Create a new profile by clicking the blue + on the icon bar in the right-hand pane.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the Intel® AMT tab check the box ‘Enable this technology in the profile'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Supply the admin user credentials set when the managed vPro systems were provisioned.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the WMI tab also check the box as above and provide a user that has admin privileges to the target system.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Give the profile a name and then save it.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Back at the main screen check the box under the ‘Default' column until the green check-mark uses your new Profile, or if you are in a job interface select the profile to be used for the run. Note that this does not require you to make it the default profile, allowing another profile to remain the default credentials.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Run the task or job to see if the authentication failure has been resolved.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If it is not, try rerunning with the Runtime Profile. This contains all known good authentication attempts to the system from either Task Server or RTSM.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In one case we supplied only AMT credentials in the Profile which allowed it to authenticate to AMT while a multiple protocol authentication profile failed. If your Task or Job does not contain any of the other protocols, this is recommended.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This concludes the Troubleshooting article series for the Altiris Manageability Toolkit for Intel vPro Technology, version 6. While this doesn't cover all issues, it should resolve most of the common issues we've seen.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:5fde44d3-a078-42bd-9f40-3a8520ea1b29] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">centrino_pro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">task_server</category>
      <pubDate>Thu, 08 May 2008 19:47:16 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/08/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-7-task-server</guid>
      <dc:date>2008-05-08T19:47:16Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-7-task-server</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11147</wfw:commentRss>
    </item>
    <item>
      <title>New known issues and best practices posted! Topics are around SCS and the SMS Add-on.</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/08/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</link>
      <description>&lt;!-- [DocumentBodyStart:5698b92c-520d-4678-bfb4-1bf6ab171941] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;New articles for you to take a look at this week. As always, let me know if you have a best practice or known issue that you want to share or have investigated!&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SCS14"&gt;Using international keyboards to create MEBx passwords via Setup and Configuration Service (SCS)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SCS15"&gt;What is the Authorized column in SCS?&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#SMS4"&gt;Do management workstations running the SMS console and SMS Add-on require patches as outlined in the documentation for the Intel(R) AMT Add-on for Microsoft SMS*?&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:5698b92c-520d-4678-bfb4-1bf6ab171941] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">sms</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">scs</category>
      <pubDate>Thu, 08 May 2008 16:50:40 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/08/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</guid>
      <dc:date>2008-05-08T16:50:40Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/new-known-issues-and-best-practices-posted-topics-are-around-scs-and-the-sms-addon</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11144</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 6 - Real-Time System Manager</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/07/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</link>
      <description>&lt;!-- [DocumentBodyStart:5f27f7ab-5600-4664-86c3-c1d483a6309e] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Formerly known as Web Admin for Windows, Real-Time System Manager provides a powerful set of functions for IT specialists. In part 5 of this article series we covered the main points for Real-Time Console Infrastructure troubleshooting. As a natural extension of RTCI, Real-Time System Manager troubleshooting is covered in this article as part 6. With an emphasis on credentials and connection methods, this article provides information to overcome the most common issues seen when using the Real-Time tab for direct, one-to-one computer interaction.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Introduction&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Real-Time System Manager provides a powerful tool for directly connecting to a system agentlessly with functionality available through WMI and Intel AMT. This article covers the issues associated with general functions seen with both technologies but with emphasis on the AMT functions. The following sections cover areas of troubleshooting:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Connection Issues&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Authentication Issues&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;IDE Redirect (IDER)&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Network Filtering&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Connection Issues&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Under the current architecture the FQDN is the primary method for connecting and authenticating to AMT on remote systems. If the FQDN the Real-Time tab is using does not resolve in DNS, then AMT connectivity and thus functionality will not be available. FQDN connectivity issues are the number one issues we see with RTSM connections to AMT.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Invalid FQDN&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;To view what FQDN the Real-Time is using, use the ‘Hardware Management' node in the RTSM tree. The following screenshot shows what AMT is using:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-11143-1382/RTSMfqdn.jpg"&gt;&lt;img height="319" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-11143-1382/620-319/RTSMfqdn.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;In this example my system is in a workgroup and reported only the hostname as the FQDN, which DNS had no trouble resolving. If this fqdn is not reachable via DNS, we won't be able to connect to the AMT functionality.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;NOTE: We use several methods, including IP address, for WMI. WMI functionality may show correctly when AMT is absent in this situation&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Use these steps to see the FQDN is the issue:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Open the Real-Time tab for the AMT system you are managing.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once the tree loads, open the Real-Time System manager folder, open Administrative Tasks, and click on ‘Hardware Management'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Once the page loads, if AMT is missing as an available technology, take note of the name displayed as in the screenshot above.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Go to Start, Run, type in cmd, and click OK.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Type in nslookup &amp;amp;lt;name displayed&amp;amp;gt;. In the above example it would read:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;Nslookup dellvpro&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Can DNS resolve this address? If no, we'll need to fix the issue in one of the following ways.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;FIX DNS and/or the Altiris record: If DNS can be fixed, this is the preferred method. The difficulty is finding out why the Altiris Agent reported the incorrect record. Once DNS is fixed, have the Altiris Agent run Basic Inventory. The table location we pull this out of for management in RTSM is Inv_AeX_AC_Location, column: &lt;a class="jive-link-external-small" href="Fully Qualified Domain Name"&gt;Fully Qualified Domain Name&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Use the ‘Manage' node available in RTSM (see the below screenshot): By putting in the IP address of the system, we'll use the IP to lookup the FQDN and not make any assumptions. &lt;br/&gt;!Manageshortcut.JPG!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Update the Servers HOSTS or LMHOSTS files to contain the mapping to the invalid name. For example find the LMHOSTS file, edit it and add a line &amp;amp;lt;IP ADDRESS&amp;amp;gt; &amp;amp;lt;FQDN&amp;amp;gt;, as in this example:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;10.10.10.1 Dellvpro&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Real-Time unable to connect&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;If WMI and AMT functions are unavailable, you'll get a message when you click on the Real-Time tab indicating that the functionality isn't available. See the following screenshot:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-11143-1383/NoRTSMavailable.jpg"&gt;&lt;img height="257" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-11143-1383/620-257/NoRTSMavailable.jpg" width="620"/&gt;&lt;/a&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Note: If you use another product such as Dell or HP's plug-ins to this tab, you'll simply not have the ‘Real-Time System Manager' node underneath Real-Time Consoles.&lt;/em&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The number one reason this occurs is due to a firewall being engaged. Firewalls need to allow AMT traffic through. If a firewall is enabled, use the following details to resolve the AMT issue:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Create an inclusion in the firewall properties.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Allow the following ports, based off your environment:&lt;/p&gt;&lt;/li&gt;&lt;ol&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;16992 - For non-TLS encrypted traffic - if you are not using TLS this is the port that will be used for communication&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;16993 - For TLS-enabled, encrypted AMT traffic - If https is required for communication with AMT, this port will be used&lt;/p&gt;&lt;/li&gt;&lt;li level="2" type="ol"&gt;&lt;p&gt;16994 - For a note, AMT provisioning uses this port for sending out the ‘hello' packet during the configuration process - this will be used if you initiate a reprovision from RTSM&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Another options is to disable the firewall when you need to manage the system via RTSM.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Unfortunately WMI has a known issue with the Windows firewall where the dynamic ports WMI uses after initiation will be blocked. It's a bug in WMI that has been addressed in Vista. Previous Operating Systems do not have a resolution at this time.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The other issue we've seen is where the system is simply unavailable for one reason or another. AMT is available if the system is off but still connected to the network, but WMI or if the system is unplugged from power or off the network RTSM obviously cannot function. Verify that the system is available if nothing resolves this issue.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Authentication Issues&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;Another common issue concerns authentication to the system via the Real-Time tab. First, let me discuss the methods RTSM uses to authenticate to a target system.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Authentication Methods&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Runtime Profile&lt;/strong&gt; - The Runtime profile contains he following information:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;All known good credentials used to connect via RTSM to a system&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;The Intel SCS AMT password sent to systems when provisioning occurs&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;Previously successfully used credentials from past RTSM sessions&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;User-defined Profiles&lt;/strong&gt; - Profiles can be created that specifically provide credentials for the four types of technologies:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;WMI digest or Domain account&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;AMT digest or Kerberos-authenticated user&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;ASF digest or Domain account&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ul"&gt;&lt;p&gt;SNMP community strings&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Manually entered credentials&lt;/strong&gt; - When RTSM tries to connect, if the default profile set in the RTCI configuration fails to authenticate, the left-hand tree will still load but each node will prompt the user for credentials. A user can put in an AMT account, Domain user, or digest user that has rights on the target system. When authentication succeeds, these credentials are then stored in the Runtime Profile for the target system.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Troubleshooting Authentication&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;The following method will help identify issues and offer ways to work-around and solutions. These have been compiled through experience when troubleshooting issues with failed authentication with RTSM.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In the Altiris Console browse to View &amp;amp;gt; Solutions &amp;amp;gt; Real-Time Console Infrastructure &amp;amp;gt; Configuration &amp;amp;gt; select Manage Credentials Profiles.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Where does the green checkmark fall? This is the default profile that will be used when connecting via the Real-Time tab.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Create a new profile by clicking the blue + on the icon bar in the right-hand pane.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the Intel® AMT tab check the box ‘Enable this technology in the profile'.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Supply the admin user credentials set when the managed vPro systems were provisioned.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Under the WMI tab also check the box as above and provide a user that has admin privileges to the target system.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Give the profile a name and then save it.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Back at the main screen check the box under the ‘Default' column until the green check-mark uses your new Profile.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Test to see if this new profile is successful. Note that you'll need to launch IE fresh to use the new settings.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;If it is not, try entering credentials in manually when you hit the system under the Real-Time tab. See the screenshot below for the connection icon to switch between WMI and AMT authentication. If two show in this area, both technologies are available but not authenticated. &lt;br/&gt;!RTSMconnectiontype.jpg!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;In one case we supplied only AMT credentials in the Profile which allowed it to authenticate to AMT while a multiple protocol authentication profile failed.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Check the collection you are launching Resource Explorer from. Sometimes the identity of the system is incorrect. For AMT you can launch RTSM from the Provisioned collections populated with the Resource Synchronization.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;IDE Redirect (IDER)&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;IDE Redirect allows a system to be remotely booted to a file, drive, or virtual disc. There are a number of potential issues to be aware of when working with IDER in a vPro environment. The below items include well-known issues and their resolutions.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;Redirection Invalid Parameter&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;When initiating an IDER (IDE Redirect) session to an external source such as an .iso file, the following error appears in the console: &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Power management operation failed.&lt;/p&gt;&lt;p&gt;Redirection session start has failed. See logs for more details.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The Notification Server log shows the following error: &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Log File Name: C:\Program Files\Altiris\Notification Server\Logs\a.log&lt;/p&gt;&lt;p&gt;Priority: 2&lt;/p&gt;&lt;p&gt;Date: 3/9/2007 2:51:05 PM&lt;/p&gt;&lt;p&gt;Tick Count: 10617218&lt;/p&gt;&lt;p&gt;Host Name: &amp;amp;lt;&amp;amp;gt;&lt;/p&gt;&lt;p&gt;Process: w3wp.exe (2436)&lt;/p&gt;&lt;p&gt;Thread ID: 5412&lt;/p&gt;&lt;p&gt;Module: AltirisNativeHelper.dll&lt;/p&gt;&lt;p&gt;Source: RTCI.Trace&lt;/p&gt;&lt;p&gt;Description: RedirectionProvider::StartIDER - RedirectionProvider::StartIDER - IMR_IDEROpenTCPSession: IMR_RES_INVALID_PARAMETER&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This is caused by Intel's redirection library requiring a correct floppy device to initiate an IDER session (either floppy image or real removable device). Real-Time System Manager 6.2 can work around this. If you put floppy.img file into &lt;em&gt;Program Files\Altiris\RTSM\UIData&lt;/em&gt; folder, then the issue will not occur.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;&lt;span&gt;IDER or SOL Disabled&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;In some instances Intel vPro systems are arriving from the OEM with IDER and SOL disabled in the BIOS. When disabled, neither of these functions work from any management engine, including RTSM. Correcting this oversight is not easy, especially if the OEMs do not offer a solution by a firmware or BIOS update. Use the following method to resolve the issue:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ol&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Go to the Support site for the OEM for the systems.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Browse to the drivers and downloads section for the exact model (note that sometimes the model will differ based on possessing or not possessing vPro technology).&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Check the firmware updates for a new BIOS.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Check the documentation for any new BIOS versions that include vPro to see if they've corrected this.&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;Contact your OEM if they have not and request a status!&lt;/p&gt;&lt;/li&gt;&lt;li level="1" type="ol"&gt;&lt;p&gt;The only other recourse is to develop an update yourself or manually update the settings by visiting the system.&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;h1&gt;&lt;span&gt;Conclusion&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;This should account for the most common issues we've seen, and allow you to successfully use RTSM with AMT technology, avoiding those issues.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:5f27f7ab-5600-4664-86c3-c1d483a6309e] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">altiris</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">amt</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">centrino_pro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">symantec</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">real-time_system_manager</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">rtsm</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">rtci</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">notification_server</category>
      <pubDate>Wed, 07 May 2008 18:18:23 GMT</pubDate>
      <author>joel_smith1@symantec.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/05/07/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</guid>
      <dc:date>2008-05-07T18:18:23Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11143</wfw:commentRss>
    </item>
    <item>
      <title>New USB provisioning article published in wiki!</title>
      <link>http://communities.intel.com/community/openportit/vproexpert/blog/2008/04/29/new-usb-provisioning-article-published-in-wiki</link>
      <description>&lt;!-- [DocumentBodyStart:668da5e9-b895-48af-a9aa-7a83f20bf26b] --&gt;&lt;div class='jive-rendered-content'&gt;&lt;p&gt;Here's an interesting one on USB provisioning -- just published in  &lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247"&gt;Known Issues, Best Practices, and Workarounds&lt;/a&gt;:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a class="jive-link-wiki-small" href="http://communities.intel.com/docs/DOC-1247#USB7"&gt;What is the maximum number of PID/PPS pairs that can be used during USB provisioning?&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:668da5e9-b895-48af-a9aa-7a83f20bf26b] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">vpro</category>
      <category domain="http://communities.intel.com/community/openportit/vproexpert/blog/tags">usb</category>
      <pubDate>Tue, 29 Apr 2008 20:45:13 GMT</pubDate>
      <author>michele.gartner@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/vproexpert/blog/2008/04/29/new-usb-provisioning-article-published-in-wiki</guid>
      <dc:date>2008-04-29T20:45:13Z</dc:date>
      <clearspace:dateToText>1 year, 7 months ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/community/openportit/vproexpert/blog/comment/new-usb-provisioning-article-published-in-wiki</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/vproexpert/blog/feeds/comments?blogPost=11113</wfw:commentRss>
    </item>
  </channel>
</rss>

