Home > Intel Communities > Open Port IT Community > Intel® vPro™ Expert Center > Microsoft Manageability > Blog > Tags > configmgr

Microsoft Manageability

11 Posts tagged with the configmgr tag
0

Microsoft System Center Configuration Manager can provision an AMT / vPro client in two different capacities: Bare metal and Agent Initiated.  Bare metal provisioning begins with the AMT client sending a “hello packet” to the SCCM Out of Band Service Point; if the AMT client is approved and authorized to be provisioned, SCCM will initiated the provisioning process.  Agent Initiated provisioning begins with the SCCM Client Agent pulling down the “Automatic Provisioning” policy from the SCCM Policy Server; if the SCCM Client Agent receives the policy, the Agent will negotiated a One Time password (OTP) with the AMT ME firmware and send the provisioning request along with the OTP to the Out of Band Service point to begin the provisioning process.


Bare Metal / Hello Packet Initiated Provisioning
For Bare Metal provisioning to work properly on AMT / vPro Clients with firmware 2.x, there are a couple of prerequisites that must be met.


SCCM Server


AMT Client

  • AMT Firmware version that support PKI provisioning with SCCM.  For AMT 2.x Desktops and Laptops, you will want to ensure that you have a minimum of AMT Firmware 2.2.20 (Desktop) and 2.2.20 (Laptop).  Note: For AMT Desktops with firmware 3.x, you will want to ensure that you have firmware 3.2.2 or above to meet the minimal requirements.  AMT Laptops with firmware 4.x and Desktops with firmware 5.x have the minimum requirements meet from the initial firmware release.

 

SCCM Client Agent Initiated Provisioning
In addition to the prerequisites needed for Bare Metal provisioning, SCCM Agent initiated provisioning requires a couple additional items.


AMT Client

  • AMT ME / HECI Driver installed (available from your OEM driver website)
  • Execution of RNGSeedCreator.exe (Download available from here: http://communities.intel.com/docs/DOC-3807).  RNGSeedCreator.exe is an executable that is ran on an AMT / vPro client with firmware version 2.x that has never been configured or provisioned; this utility generates a random number for the firmware to support the OTP used during the SCCM Agent Initiated Provisioning process.  For SCCM PKI provisioning to complete successfully, the random number generated by RNGSeedCreator.exe must be completed prior to initiating provisioning via the SCCM Client Agent.Note: AMT / vPro clients with firmware version 3.x and higher do not need to have the RNGSeedCreator.exe ran prior to SCCM Agent Initiated provisioning.

 

 

If your AMT clients do not meet the minimal firmware version for PKI based provisioning (Bare Metal or Agent Initiated), you can use the software distribution capabilities within SCCM to remotely upgrade the AMT firmware and drivers; check out the following Blog / Video which walks you through creating this software package.  Similar to upgrading the AMT firmware with SCCM Software distribution, you can also use the same Software Distribution process to run the RNGSeedCreator.exe utility on your 2.2 (Desktop) and 2.6 clients.  If you wish to combine the firmware upgrade and RNGSeedCreator.exe execution into a single SCCM advertisement, you can construct a single task sequence that runs both the Firmware upgrade and RNGSeedCreator.exe software packages.  A guide on how to accomplish this has been included in the RNGSeedCreator download package.

 

 

Once the firmware has been upgraded to the minimal firmware version to support PKI provisioning and the RNGSeedCreator.exe has been run, SCCM Agent Initiated provision can complete successfully on 2.2 and 2.6 clients.


--Matt Royer

0 Comments Permalink
2

Here is a demonstration I created on how to setup a SCCM advertisement to remotely and securely wake-up (boot) Intel vPro systems and push an automated BIOS upgrade.  I wanted to show a useful and real-world Intel vPro Use Case that you can use today.  If there are other Use Cases you would like to see, please post your comments and I will get more of these types of videos posted.

 

Thanks,

Bill

 

2 Comments Permalink
1

In order for Microsoft Systems Center Configuration Manager to provision a vPro system, via bare-metal provisioning, it needs to know its UUID (Also referred to as a GUID), MAC address, short name and FQDN.  This information can be collected into a CSV file and imported into SCCM manually, or automatically by leveraging a script and WMI.  This package will outline the security configuration and point you to resources you can use to create a script to automate this process.  You can get a copy here:

 

Update 6/25/2009:  An updated version of the script is available at the link below.

 

http://communities.intel.com/docs/DOC-3067

1 Comments Permalink
6

Microsoft SCCM 2007 SP1 Intel vPro Training Videos

We’re pleased to announce the availability of Microsoft SCCM 2007 SP1 Intel vPro Training videos. During a recent training event in Redmond, Washington, we had the cameras rolling for this detailed and robust training experience and it is now available for you to experience and utilize.

 

Below is an overview and link for each training section.

 

Introduction

 

Technical overview of Microsoft System Center Configuration Manager 2007 SP1 support of Intel vPro technology with specific focus on supported use cases, provisioning process and infrastructure prerequisites for Intel vPro Out of Band Management.

Lab Module One

 

Configuration steps of Active Directory and PKI infrastructure to support Intel vPro Out of Band Management within Microsoft System Center Configuration Manager 2007 SP1.

Lab Module Two

 

Steps for Microsoft System Center Configuration Manager 2007 SP1 OOB Service Point installation, OOB Component Configuration and Network Discovery for Management Controllers.

Lab Module Three

 

Steps for creating a collection for housing Intel vPro clients and configuring that collection for automatic provisioning of the Out of Band Management Controllers.

Lab Module Four

 

Installation overview for the Microsoft System Center Configuration Manager 2007 SP1 client agent and initiation of Intel vPro client provisioning.

Lab Module Five

 

Technical overview of the Out of Band Management Console, Intel vPro Management Engine Interface and Intel AMT power control via Advertisements.

Lab Module Six

 

Configuration steps of the Intel WS-MAN Translator to support legacy Intel vPro clients (Intel AMT firmware versions less than 3.2.1).

Lab Module Seven

 

Provisioning legacy Intel vPro clients (Intel AMT firmware versions less than 3.2.1) through the Intel WS-MAN Translator using PSK provisioning.

Lab Module Eight

 

Overview of the Intel vPro migration process from the Intel SCS / Microsoft SMS 2003 Add-on to Microsoft System Center Configuration Manager 2007 SP1.

 

Please let us know if you have questions or comments regarding this material.

 

This resource along with other resources on the Intel vPro Expert Center can assist you in answering questions when deploying Intel vPro clients in conjunction with Microsoft System Center Configuration Manager 2007 SP1.

6 Comments Permalink
0

At MMS, Kiron Lahiri, Lead Systems Engineer for Client Systems, and Brian Boresi, Information Services Division, both with Sisters of Mercy Health System, talked about some of the powerful benefits of combining Intel vPro technology with Microsoft System Center Configuration Manager. Listen to the video and see how Sisters of Mercy Health System is benefiting from this combination of hardware and software in their infrastructure.

 

 



]]>

 

To see more videos from MMS, go to http://www.intel.com/go/mms/

0 Comments Permalink
0

While at MMS, we talked to two Service Integrators about Intel vPro technology with System Center 2007 - including the combination of Intel® vPro™ technology with System Center Configuration Manager 2007 for medium to large businesses and the combination of Intel® vPro™ Technology with System Center Essentials 2007 for small businesses.

 

 



]]>

 

To see more videos from MMS, go to http://www.intel.com/go/mms/

0 Comments Permalink
0

While at MMS, Microsoft System Center Configuration Manager Program Manager Dave Randall demonstrated how Intel vPro Technology enhances Microsoft System Center Configuration Manager 2007 SP1. The videos below include demonstrations around secure remote power control, remote diagnosis and repair of troubled PCs, discovery of PC assets, and remote configuration.

 

1) Video demonstration of hardware-assisted Secure Remote Power Control:

 

 



]]>

 

 

2) Video demonstration of hardware-assisted Remote Diagnosis and Repair:

 

 



]]>

 

 

3) Video demonstration of hardware-assisted Discovery of PC Assets:

 

 



]]>

 

4) Video demonstration of Remote Configuration of Intel vPro technology:

 

 



]]>

 

 

Click here to learn more about the combination of Microsoft System Center 2007 products with Intel vPro technology: http://communities.intel.com/community/vproexpert/microsoft-vpro

0 Comments Permalink
0

While at MMS, we had the opportunity to talk with D.C. Tardy, System Architect at EDS. He talked about the Return On Investment of Intel vPro technology, including a Canadian Call Center case study that returned a savings of almost $750,000 across 3 years. He also talked about the combination of System Center Configuration Manager with Intel vPro technology.

 

 



]]>

 

To see more videos from MMS 2008, go to http://www.intel.com/go/mms/

0 Comments Permalink
0

At MMS, we had Brad Anderson, General Manager of Microsoft Management and Services Division, and Gregory Bryant, Intel VP and General Manager of the Digital Office Platform Division, answer some questions about the new capabilities in System Center Configuration Manager 2007 SP1 with Intel vPro technology. See their responses below.

 

1) How does Intel vPro Technology fit into System Center Configuration Manager 2007 SP1?

 

 



]]>

 

 

2) What can IT expect in terms of the level of integration of Intel vPro Technology into System Center Configuration Manager 2007 SP1?

 

 



]]>

 

3) Why should IT now take advantage of Intel vPro Technology and System Center Configuration Manager 2007 SP1?

 

 



]]>

 

4) When should enterprises activate Intel vPro Technology with System Center Configuration Manager 2007 SP1 in their PC infrastructure?

 

 



]]>

 

5) Last, we asked a series of questions about System Center Configuration Manager 2007 SP1 Support for the Current Generation of Intel vPro Technology with WS-MAN Support, as well as with Legacy Generations of Intel vPro technology.

 

 



]]>

 

To see more videos, demonstrations, interviews and more from MMS 2008, go to http://www.intel.com/go/mms/

0 Comments Permalink
0

 

In Josh's blog post about "Stump the PRO" - he mentions WMI & ConfigMgr. I wanted to post a bit more context for everyone interested in that integration point.

 

 

Overview: ConfigMgr client agent uses WMI to query AMT via the HECI driver.

 

 

The Configuration Manager client agent ships with a new WMI provider for the AMT HECI driver. Additionally, we have extended the SMS_DEF.MOF file with new classes that support the WMI provider. This is used by the hardware inventory agent when returning information about the client computer. You'll find the data easily for your AMT computers using the resource explorer for an AMT computer. The information is categorized under a new resource called "AMT Agent"

 

 

The inventory from that agent make a great basis for building queries to use the in-band agent based provisioning method.

 

 

Dave

 

 

0 Comments Permalink
1

Hello to the vPro community!

 

I'm David Randall, and have been working in the Configuration Manager team over the last year to develop our integration with Intel's AMT hardware.

 

 

I recently attended MMS 2008, and was very happy to hear all the enthusiasm around the Configuration Manager integration, and your plans to use vPro in conjunction with ConfigMgr.

 

 

I plan to post here weekly with new information that we've learned about ConfigMgr / AMT integration, help you with some walk throughs, list interesting new uses for vPro and where possible, help you streamline your Configuration Manager deployment with vPro.

 

 

Thanks, and here's to out of band management!

 

 

David Randall

Program Manager, Microsoft

 

 

1 Comments Permalink