<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Intel vPro Expert Center Blog</title>
    <link>http://communities.intel.com/openport/blogs/proexpert</link>
    <description>Intel vPro Expert Center Blog</description>
    <pubDate>Tue, 08 Jul 2008 14:52:16 GMT</pubDate>
    <generator>Clearspace 1.7.0 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2008-07-08T14:52:16Z</dc:date>
    <item>
      <title>Altiris and Intel vPro Use Cases - Part 4 - Auditing and Software Remediation</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/07/08/altiris-and-intel-vpro-use-cases-part-4-auditing-and-software-remediation</link>
      <description>&lt;p /&gt;
NOTE: If you have not read parts 1 through 3, please read these before reading this part as this is a continuation of the story begun in the previous sections. &lt;a class="jive-link-external" href="http://juice.altiris.com/node/4687%20"&gt;Altiris and Intel vPro Use Cases&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Security is only as tight as the weakest link in your environment. More often than not it's internally where the security holes are created, either inadvertently from carelessness or intentionally from a disgruntled or disillusioned employee. The hardware and software security can be top of the line, but if the human factor doesn't adhere to policy, it may not make any difference. This part follows the IT team for Mighty Modern Marketing as they try to track down a security hole where productivity is taken down through the very tools used to defend and manage the network.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;Mighty Modern Marketing HQ - Boston, Massachusetts&lt;/h2&gt;
Somehow the air inside the building congealed hotter than the heavy, humid swelter wallowing outside. Tevita, sweat running down the sides of his face, fanned himself with an empty binder. He stared at his screen, the image thereon frozen.&lt;br /&gt;
&lt;br /&gt;
"I think one of the servers seized up," he said. Jessica Langley glanced at her Remote Desktop window. The previously blinking text icon in the script she edited no longer blinked, and as she watched the disconnected icon appeared, the remote screen graying-out. She closed it with a quick click of the white on red X.&lt;br /&gt;
&lt;p /&gt;
She took a long drink of water. "If they don't fix the AC soon, I'm going home," she announced.&lt;br /&gt;
&lt;p /&gt;
"They'll have it up soon. Besides, it's never been so quiet here. I only have one system running, and I think I'm approaching something like Zen. Either that or I'm about to pass out."&lt;br /&gt;
&lt;p /&gt;
"Any more missing application tickets?"&lt;br /&gt;
&lt;p /&gt;
Tevita groaned. "Oh yeah. Five so far today. It's like the uninstall faerie ran around randomly touching computers with her magic star-wand. I've taken care of it."&lt;br /&gt;
&lt;p /&gt;
Jessica stood, feeling sodden. "Thanks. I'll check on Bobby to make sure he hasn't suffered from heat stroke."&lt;br /&gt;
&lt;p /&gt;
The server room actually felt cooler despite the cacophony of running servers that reminded her of the sound and feel of a jet engine escalating towards takeoff. Somehow Bobby had created a wind tunnel with large fans, and she felt her hair whip away from her as she stepped directly in the wind's path. She shielded her eyes and walked to the developer's cube area. The pull of the moving air seemed to try and yank her off her feet by her dress-suit jacket. She folded her arms as she stepped into the relative stillness of the cube.&lt;br /&gt;
&lt;p /&gt;
Bobby looked like a wilted plant. He looked up, and sighed. "What, IM down again?"&lt;br /&gt;
&lt;p /&gt;
"Of course not," she responded with a smile. "You holding up in here?"&lt;br /&gt;
&lt;p /&gt;
He shrugged. "I'll survive, though it reminds me of Phoenix, Arizona, except here it's like standing in front of a vat of boiling water. Phoenix is like standing in front of the open door to a blast furnace."&lt;br /&gt;
&lt;p /&gt;
"The SQL Server locked again."&lt;br /&gt;
&lt;p /&gt;
Bobby nodded. "I did a hard reset just a minute ago. I had to open the case and point a fan right at the CPUs. I think it'll stay up this time."&lt;br /&gt;
&lt;p /&gt;
"Good."&lt;br /&gt;
&lt;p /&gt;
Bobby shrugged again. He looked back at his screen, then back up at her. "You need something else?"&lt;br /&gt;
&lt;p /&gt;
"Not really. You want to go to lunch with Tevita and I? The local Italian place has great AC."&lt;br /&gt;
&lt;p /&gt;
"No, I'm good. My lunch cooked itself in this heat, so I ate already."&lt;br /&gt;
&lt;p /&gt;
"Alright. See you later."&lt;br /&gt;
&lt;p /&gt;
When she returned Tevita still sat in front of his computer, sweating profusely. He looked up as she passed by, a frown on his face.&lt;br /&gt;
&lt;p /&gt;
"The facilities guy just passed by," he said as she sat down. "He says someone deliberately messed with the AC. He's fixed and says it'll be up and running any time now."&lt;br /&gt;
&lt;p /&gt;
"Someone sabotaged the AC?" she inquired.&lt;br /&gt;
&lt;p /&gt;
"Yep."&lt;br /&gt;
&lt;p /&gt;
She sighed. "Just when I thought we were done with the underhanded antics."&lt;br /&gt;
&lt;p /&gt;
Tevita nodded. "The AC guy put thick padlocks on all the control panel cases. Too bad we don't have any way to track who goes in and out of that room. A magnetic badge reader would work."&lt;br /&gt;
&lt;p /&gt;
The next hour passed in receding misery as the AC kicked on and began liberating the employees in Might Modern Marketing's Headquarters from oppressive heat. Jessica checked the Altiris Notification Server Logs, ignoring the SQL errors for the times the SQL server seized up. Except for an occasional error where an event arrived for a package already deleted from the Notification Server, the logs looked clean.&lt;br /&gt;
&lt;p /&gt;
"Mrs. Langley," Edgar's dry tones greeted.&lt;br /&gt;
&lt;p /&gt;
Right on cue, she thought. Despite the heat things had been going too smoothly. She turned around and stood.&lt;br /&gt;
&lt;p /&gt;
"Hello Edgar."&lt;br /&gt;
&lt;p /&gt;
"I wanted to let you know that the budget we set aside for the mess with New Nifty Networks is on target, thanks to everyone's diligence," he said, eyes briefly moving down to the papers clasped in his hands. "We've even been able to devote some resources to Legal. It won't be long before we can put this whole ordeal behind us."&lt;br /&gt;
&lt;p /&gt;
Tevita rolled over in his chair. "What, and I've done nothing?" The expression on his face and tone of his voice took away any sting of the words.&lt;br /&gt;
&lt;p /&gt;
"Both of you have performed exceptionally," Edgar said, shuffling the papers in his hands. "Though it's not official, I believe you will both receive a merit increases for your performances."&lt;br /&gt;
&lt;p /&gt;
"You're kidding!"&lt;br /&gt;
&lt;p /&gt;
"I do not kid, Mr. Tatafu."&lt;br /&gt;
&lt;p /&gt;
"So be honest, was it hard to allow that through?"&lt;br /&gt;
&lt;p /&gt;
The barest hint of a smile touched the corners of Edgar's thin lips. "Yes, adding my approval felt much like pulling out stitches. Now don't you both have work to do?"&lt;br /&gt;
&lt;p /&gt;
He shuffled away, his posture a little bent.&lt;br /&gt;
&lt;p /&gt;
Tevita gave Jessica a thumbs up. "Ha! So some good is coming from this whole competition nightmare."&lt;br /&gt;
&lt;p /&gt;
"Perhaps," she said noncommittally, having trouble suppressing a smile. "It's not over yet, not until this school-friend of Mr. Johnson's finally gives up. I'm hoping it happens soon so we can go back to normal."&lt;br /&gt;
&lt;p /&gt;
"Normal?" countered Tevita. "When is IT work normal? It changes faster than the seasons."&lt;br /&gt;
&lt;p /&gt;
She opened her mouth to respond when her telephone rang. The caller ID noted Johnson. She quickly picked up the handset.&lt;br /&gt;
&lt;p /&gt;
"Mighty Modern Marketing, this is Jessica," she greeted as cheerily as she could.&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Jessica, this is Mr. Johnson,"&lt;/i&gt; greeted the CEO. &lt;i&gt;"Can you please come up to my office immediately? We have a sensitive matter to discuss."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"Of course. I'll be up right away."&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Please have Tevita join us as well. See you in a minute."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"Will do. Thanks. Bye."&lt;br /&gt;
&lt;p /&gt;
When she looked up Tevita had his day planner in one hand, the other locking his computers.&lt;br /&gt;
&lt;p /&gt;
"Ready for lunch?" he inquired.&lt;br /&gt;
&lt;p /&gt;
"Change of plans," she said, rising. "Mr. Johnson wants to see us in his office immediately."&lt;br /&gt;
&lt;p /&gt;
Tevita stared at her for a moment, then tossed in planner onto his chair, a wry smile twisting his mouth. "Wonderful. Somehow even though everything he says sounds enthusiastic and wonderful, we end up with a pile of work."&lt;br /&gt;
&lt;p /&gt;
"Job security," she responded.&lt;br /&gt;
&lt;p /&gt;
The CEO's office, remarkably, looked very much like the other offices in the entire building. She glanced through the window on the door, then knocked politely. Mr. Johnson, looking as refreshed and lively as ever, waved her in. The building continued to cool, but still hovered near eighty degrees. Though she felt sweaty and rumpled, Mr. Johnson appeared completely unaffected by the heat, his hair perfectly combed and his clothing pressed and clean. He smiled warmly as they sat down in the two chairs set before his desk.&lt;br /&gt;
&lt;p /&gt;
A man sat next to him, and though she knew she should know who he was, she couldn't place his face in her memory.&lt;br /&gt;
&lt;p /&gt;
"Thank you for coming up so quickly," he said, rising to shake their hands. "This is Dan Williams, Chief Security Officer."&lt;br /&gt;
&lt;p /&gt;
She said hello, shaking Dan's hand. Funny how she knew the name so well from countless emails and conference calls. She felt she knew him despite only seeing him on rare occasions, all from electronic or audio correspondence. Somehow she'd never put that voice with this face.&lt;br /&gt;
&lt;p /&gt;
"Jessica, Tevita," he said in way of greeting in that familiar voice. "We need to meet more often, especially with how much I depend on both of you."&lt;br /&gt;
&lt;p /&gt;
"Definitely," Tevita responded as he sat down.&lt;br /&gt;
&lt;p /&gt;
Jessica had trouble controlling a laugh that threatened to escape. "Mr. Williams, you don't look like I imagined."&lt;br /&gt;
&lt;p /&gt;
Dan smiled, amusement dancing in his eyes. "What did you think I looked like?"&lt;br /&gt;
&lt;p /&gt;
She blushed. "Well... you sound like Chuck Norris. But you're more like..."&lt;br /&gt;
&lt;p /&gt;
Mr. Johnson started. "Chuck...?" He burst into laughter. Tevita's booming laughter joined in as Dan's smile grew wry. Jessica wondered if someone could faint from embarrassment, and imagined she looked as red as a tomato.&lt;br /&gt;
&lt;p /&gt;
"Sorry, I like yoga, but not much of a martial arts guy," Dan said, trying not to laugh.&lt;br /&gt;
&lt;p /&gt;
"Alright," Johnson said with a deep calming breath. "Without further preamble, I'll let Dan discuss the situation."&lt;br /&gt;
&lt;p /&gt;
Dan nodded. "As you are well aware of our situation with our friends over at New Nifty Networks, what I'm about to show you shouldn't come as much of a surprise. We have a plant."&lt;br /&gt;
&lt;p /&gt;
"A plant?" Tevita inquired. "Like a house plant?"&lt;br /&gt;
&lt;p /&gt;
Jessica covertly elbowed him in the ribs as he chuckled.&lt;br /&gt;
&lt;p /&gt;
Dan continued, undaunted. "Someone here is feeding information to our competitor. We're tracking this using email, etc, but the trail is long and convoluted. We think this spy, for lack of a better term, is also sabotaging our business here. While we're pretty sure he or she disabled the air conditioning, we don't have enough data to even begin to narrow down who it could be. There are other things happening that I believe you'll be able to help us with.&lt;br /&gt;
&lt;p /&gt;
"You see, we believe he's somehow obtain access to your management tools. We've had increased cases where vital software has been mysteriously uninstalled from systems."&lt;br /&gt;
&lt;p /&gt;
Jessica exchanged a look with Tevita. "We have had a large amount of emergency software deployment tickets," she said.&lt;br /&gt;
&lt;p /&gt;
"The tickets always say the shortcut is missing," Tevita added.&lt;br /&gt;
&lt;p /&gt;
"Exactly," Dan continued. "Depending on the user, this can severely hamper our productivity. Since some of the computers are locked behind office doors I'm assuming they're using management software to accomplish this. Is Altiris capable of this?"&lt;br /&gt;
&lt;p /&gt;
"Yes," Jessica answered. "However you need rights to do anything."&lt;br /&gt;
&lt;p /&gt;
"And that will be to our advantage. Please look through any auditing or logging done by Altiris and see if you can figure out how this individual is uninstalling applications, what credentials he or she is using. Any evidence or data you capture please forward to me."&lt;br /&gt;
&lt;p /&gt;
"We will," Tevita responded.&lt;br /&gt;
&lt;p /&gt;
Back at her desk, Jessica pulled up the Altiris Console. Events would allow her to see if any Software Delivery or similar jobs had been schedule to run on the affected systems. They had uninstall-programs setup for most of their managed applications. She browsed in the Altiris Console under View, Solutions, Software Delivery, Tasks, Windows, Software Delivery Tasks. The first task she choose uninstalled their accounting software, one application the spy or whatever he or she was liked to target. She did a quick scan to ensure no new tasks showed up.&lt;br /&gt;
&lt;p /&gt;
She clicked on the Status tab. Once the tab loaded she used the dropdown labeled, "Display computers on which this task ran:" to set it to "All". Once the grid loaded she clicked on the top of the "Attempt Time" column to sort by date, and looked at the last week's runs. Only three showed up, and all of them had been scheduled by either her or Tevita.&lt;br /&gt;
&lt;p /&gt;
"Any luck?" Tevita asked, his head rising above his cube's wall.&lt;br /&gt;
&lt;p /&gt;
"Nothing yet. I guess it's possible they created a task and then deleted it after each execution."&lt;br /&gt;
&lt;p /&gt;
"Yeah, but there's an ItemDeleted table that we can look at to see if that's occurred."&lt;br /&gt;
&lt;p /&gt;
He walked into her cube and sat down on the spare chair. He used her secondary system to open SQL Enterprise Manager and launch a query window. He used the query:&lt;br /&gt;
&lt;p /&gt;
SELECT ItemName FROM ItemDeleted&lt;br /&gt;
&lt;p /&gt;
WHERE ItemName LIKE &amp;lsquo;%Accounting%'&lt;br /&gt;
&lt;p /&gt;
AND ItemClassGuid = &amp;lsquo;D922981C-B8E7-40EE-B6BD-1E6CB354C9FE'&lt;br /&gt;
&lt;p /&gt;
"This class-guid here represents Software Delivery Tasks," Tevita explained as he ran the query. "Nope, nothing. Let me try one more query, this one more generic..."&lt;br /&gt;
&lt;p /&gt;
SELECT * FROM ItemDeleted&lt;br /&gt;
&lt;p /&gt;
WHERE ItemClassGuid = &amp;lsquo;D922981C-B8E7-40EE-B6BD-1E6CB354C9FE'&lt;br /&gt;
&lt;p /&gt;
ORDER BY DeletedDate&lt;br /&gt;
&lt;p /&gt;
"Okay," he continued. "I don't think he used Software Delivery. I don't see any Tasks deleted recently enough to account for all the uninstalls reported."&lt;br /&gt;
&lt;p /&gt;
Jessica nodded. "Hmm. If he didn't use this, then the only other two options I can think of are Deployment Server and Task Server."&lt;br /&gt;
&lt;p /&gt;
Tevita smiled. "No chance with Deployment Server. I've changed the management credentials recently and blocked everyone else out. Since only you and I use it, I figured with all the security stuff going on I'd better be safe, not sorry."&lt;br /&gt;
&lt;p /&gt;
She blinked. "I didn't know you'd locked... I guess DS is your baby."&lt;br /&gt;
&lt;p /&gt;
"You know it. So, do you think Task Server could really be it? Wouldn't he need to know scripting?"&lt;br /&gt;
&lt;p /&gt;
"Not necessarily. There's a &amp;lsquo;Deliver Software' task available that can run any Package-Program we have available in Software Delivery. Let me look through here... I don't see any Jobs or Task Server tasks that reference the uninstall program. The ItemDeleted would have deletions if he'd done that. But you used the standard Software Delivery Tasks, right? Can you do one for Task Server Tasks?"&lt;br /&gt;
&lt;p /&gt;
Tevita scratched his chin. "I think so. In fact we don't delete things that often. Let's try this..."&lt;br /&gt;
&lt;p /&gt;
SELECT * FROM ItemDeleted&lt;br /&gt;
&lt;p /&gt;
ORDER BY DeletedDate&lt;br /&gt;
&lt;p /&gt;
"Okay. A few deletions, but they all look straight-forward. Computers purged, a couple of Software Portal Requests... but nothing that looks like a Task Server task. Wait... what's this? Bobby deleted a task named WOfW? This was last week. If I didn't know better, I'd say he's been playing with Software Delivery and Worlds Of Warcraft."&lt;br /&gt;
&lt;p /&gt;
Jessica grinned. "You think he wants to roll it out company-wide? I can see it now. &amp;lsquo;Productivity hits an all-time low, though the average level of Mighty Modern Marketing exceeds fifty'!"&lt;br /&gt;
&lt;p /&gt;
Tevita laughed, pointing at her. "I didn't know you knew enough about gaming to make a joke like that!"&lt;br /&gt;
&lt;p /&gt;
"Right. Like you don't bring it up every week. It was bound to rub off on me at least a little."&lt;br /&gt;
&lt;p /&gt;
"This looks clean. That doesn't make sense. Perhaps Dan's wrong, and whoever's responsible for this isn't using Altiris."&lt;br /&gt;
&lt;p /&gt;
Jessica shook her head. "He's right, I don't think this could be done at this rate any other way. Either they're using a different method, or they have intimate knowledge of Altiris."&lt;br /&gt;
&lt;p /&gt;
Tevita leaned back, looking up at the ceiling. Jessica placed a fingertip on her lips, thinking furiously. If Software Delivery and Task Server wasn't used, and the evidence suggested such, what other method could you use to remove software? They planned on using PC Anywhere for remote control, but it wasn't up and running yet in the Altiris environment. Tevita used the simple Remote Control feature in Deployment Server, and she still used Carbon Copy. She'd disabled access to it in Altiris and used the stand-alone product that only existed on her system for security reasons. Could they have a rogue copy of Carbon Copy installed...?&lt;br /&gt;
&lt;p /&gt;
"What about vPro?" Tevita inquired abruptly, interrupting her thoughts.&lt;br /&gt;
&lt;p /&gt;
"Serial-Over-LAN doesn't work in Windows currently," she responded. "No other remote application abilities... it's really considered an out of band management interface."&lt;br /&gt;
&lt;p /&gt;
"Yeah, but if you built a remote tool into an ISO, using IDER, couldn't you use that?"&lt;br /&gt;
&lt;p /&gt;
"In theory, yes... In fact if you ran an IDE redirect with something like that you could do whatever you wanted to the system."&lt;br /&gt;
&lt;p /&gt;
"Exactly."&lt;br /&gt;
&lt;p /&gt;
Jessica smiled. "And we have an actual activity log."&lt;br /&gt;
&lt;p /&gt;
In the Altiris Console she browed in View, Solutions, Real-Time Console Infrastructure, Tools, and clicked on "Activity Log". She scanned down the entries.&lt;br /&gt;
&lt;p /&gt;
"Well, well," Tevita said, leaning forward. "Our friend has been busy."&lt;br /&gt;
&lt;p /&gt;
The icon showing a redirection session appears like two plugs plugged together. The other pertinent columns appeared as "client": showing what computer by IP Address is being accessed, "user": what credentials were used to execute the action, Host: as in the hostname of the destination computer, Description: showing the path to the ISO, and lastly Technology showing what method was used. Multiple RTSM sessions showed a redirection to an ISO labeled: RemoteControl.iso. The path led to a UNC share.&lt;br /&gt;
&lt;p /&gt;
Jessica pulled up the contents. "Jackpot."&lt;br /&gt;
&lt;p /&gt;
Tevita shook his head. "Too easy. If they know how to create ISOs of that nature and use RTSM to deploy them, did they actually think there wouldn't be some sort of logging?"&lt;br /&gt;
&lt;p /&gt;
"I don't know. RTSM is unique in that it isn't dependent on an agent at all, so there is no logging client-side. Still... perhaps whoever's doing this didn't create the ISOs and is just in charge of running it. And we aren't done yet. Note that the User is all listed as admin. This means he or she is using the AMT credentials available on all systems."&lt;br /&gt;
&lt;p /&gt;
"Oh. Can't exactly blame the invisible AMT admin..."&lt;br /&gt;
&lt;p /&gt;
"No, but we can change the password easily. Before I do that, I'll send Dan the information on the share. That share should have some sort of user footprint his team can get to."&lt;br /&gt;
&lt;p /&gt;
She quickly sent the email with all the information. She explained that she would change the admin password so that this rogue user could no longer use this method. After sending it she browsed in the Altiris Console to View, Solutions, Out of Band Management, Configuration, Provisioning, Configuration Service Settings, and selected Provision Profiles. She double-clicked on the profile they used for all systems. Under the Administrator Credentials section to the right, she changed the password under the Manual radial option. She clicked OK to save the changes.&lt;br /&gt;
&lt;p /&gt;
Next she browsed back up to Provisioning, and into Intel AMT Systems, selecting the node Intel AMT Systems. When the frame loaded, she clicked on the icon on the icon bar that looked like a system with refresh green arrows surrounding it, labeled: Re-provision. She hadn't selected any systems so she selected the only live option, "All systems". She clicked OK to execute.&lt;br /&gt;
&lt;p /&gt;
"That should do it," she said aloud.&lt;br /&gt;
&lt;p /&gt;
"A re-provision?" Tevita asked.&lt;br /&gt;
&lt;p /&gt;
"It's a simple way to send down the changes in a profile to the systems. It'll take some time to cycle through all the systems, but soon all systems will have the new AMT admin password set."&lt;br /&gt;
&lt;p /&gt;
Tevita leaned back. "So we're done?"&lt;br /&gt;
&lt;p /&gt;
"For now, unless you have any ideas for further tracking this guy...?"&lt;br /&gt;
&lt;p /&gt;
The rest of the day proceeded smoothly, with only one more reinstall helpdesk ticket coming in. By the next day no new tickets had developed, and things had settled down to normal. Dan said he had enough to identify the perpetrator, but said no more on the subject. &lt;br /&gt;
&lt;p /&gt;
He did say one thing very firmly. "All the security we can muster is worthless if those with the right privileges are not careful with their credentials."&lt;br /&gt;
&lt;p /&gt;
Further, he requested they review their procedures concerning the AMT admin password. Was it written down anywhere? Did they ever say it out-loud? Though neither knew how the password got originally stolen, the increased care with which they handled passwords became a driving program within the company. Security was everyone's job.&lt;br /&gt;
&lt;p /&gt;
At the end of the week, as Jessica headed away from Boston on the Redline Commuter Train, she hoped they'd seen the end of the targeted attacks, but in her mind she already looked through her current policies and processes to see where she could increase security.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;End Part IV&lt;/h2&gt;
Altiris provided not only an audit trail to track potential rogue usage of RTSM, but it also provided a very quick and efficient way to change security within AMT when somehow the credentials are compromised. Is this the end of the threats against Mighty Modern Marketing? Only time will tell.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">manageability</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">task_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">notification_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">real-time_system_manager</category>
      <pubDate>Tue, 08 Jul 2008 15:05:24 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/07/08/altiris-and-intel-vpro-use-cases-part-4-auditing-and-software-remediation</guid>
      <dc:date>2008-07-08T15:05:24Z</dc:date>
      <clearspace:dateToText>1 month, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/altiris-and-intel-vpro-use-cases-part-4-auditing-and-software-remediation</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11331</wfw:commentRss>
    </item>
    <item>
      <title>Altiris and Intel vPro Use Cases - Part 3 - Hardware</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/07/02/altiris-and-intel-vpro-use-cases-part-3-hardware</link>
      <description>&lt;p /&gt;
If you have not read parts 1 and 2, please read these before reading this part as this is a continuation of the story begun previously.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;a class="jive-link-external" href="http://juice.altiris.com/book/4687/altiris-and-intel-vpro-use-cases"&gt;http://juice.altiris.com/book/4687/altiris-and-intel-vpro-use-cases&lt;/a&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
From the OS level vPro has tools to help quarantine and remediate compromised systems as demonstrated in part 2. This section explores the capabilities at the hardware layer, completely below the OS and any related dependencies. Can the IT staff continue to respond well to threats and avoid outages and threats to the businesses wellbeing? When the gloves come off sometimes even the most secure networks are vulnerable to threats.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;Mighty Modern Marketing HQ - Boston, Massachusetts&lt;/h2&gt;
"This is Jessica, how can I help you?"&lt;br /&gt;
&lt;br /&gt;
The voice that spoke through the headset caused her to flinch, and she moved the earpiece two inches away from her ear.&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"This can't be happening now!"&lt;/i&gt; the voice exclaimed loudly.&lt;br /&gt;
&lt;p /&gt;
"What's the problem?" she responded calmly, hoping the user would match her volume.&lt;br /&gt;
&lt;p /&gt;
He didn't. &lt;i&gt;"The timing is the worst possible, since the end of quarter is only two days away! I need my computer up and running two hours ago!"&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"Let me see... I'm speaking to Mitch Cavanaugh, correct?"&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Yes,"&lt;/i&gt; he responded, his voice dropping a trifle. &lt;i&gt;"My computer isn't booting, and I have sales to approve and record. If I don't get this up quick, we may not be able to add this revenue this quarter!"&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"I understand," she said as she used the Altiris Console under the All Computers Collection to find his computer. She double-clicked on it, bring up Resource Manager.&lt;br /&gt;
&lt;p /&gt;
"I see you're using an HP 7800..." she began.&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"I need this problem fixed pronto,"&lt;/i&gt; he interrupted.&lt;br /&gt;
&lt;p /&gt;
"Of course," she said, clicking on the &amp;lsquo;Real-Time' tab. "Give me just a moment."&lt;br /&gt;
&lt;p /&gt;
She smiled, feeling a warmth from the fact that she'd made sure those with the most business critical functions got the vPro systems first. The Real-time tab loaded, revealing the function tree in the left-hand pane. She noted immediately that only the AMT functions loaded, and that the system's powerstate was on.&lt;br /&gt;
&lt;p /&gt;
"I can see," she said when she heard a sound of irritation on the other line, "that while there is power to your computer, the operating system is not loading."&lt;br /&gt;
&lt;p /&gt;
A pause followed her comment. &lt;i&gt;"Really?"&lt;/i&gt; Mitch responded, the edge on his voice disappearing. &lt;i&gt;"You can tell me that already? Usually I have to tell you IT people everything... that's great. So do you know what's going on?"&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"Give me another moment," she said in her most pleasant voice. She clicked on the Hardware Management node in the left tree. After the page loaded, she choose the reboot radial under the Remote power management section. Under Redirection options she check the box, "Display task progress and remotely control computer". Next she clicked "Run Task Now". When the page began to refresh a new window popped up, showing her the boot of the computer. &lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Wait, my computer just rebooted..."&lt;/i&gt; Mitch said, sounding suspicious.&lt;br /&gt;
&lt;p /&gt;
"Yes, I just initiated a reboot," she responded. "I'm going to watch the boot from here."&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"You can do that? I thought I had to be in Windows for that to work."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
When the boot verified devices on the system she noticed that no hard drive was detected. The message "No boot device" appeared.&lt;br /&gt;
&lt;p /&gt;
"Okay Mitch, the computer isn't recognizing the hard drive for some reason. Give me a moment to check a few more things."&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Is that fixable?"&lt;/i&gt; Mitch inquired.&lt;br /&gt;
&lt;p /&gt;
"I don't know yet. Give me a moment."&lt;br /&gt;
&lt;p /&gt;
She rebooted again, but also added the "Enter BIOS on startup" option by checking the box. The remote window reappeared, this time entering the BIOS. She looked under the IDE channels, but no hard drive was listed.&lt;br /&gt;
&lt;p /&gt;
"Okay Mitch, I've determined that your hard drive isn't being detected at all by the computer. Since you have critical work to perform, we'll immediately image and restore your data to a backup system using Deployment Server and Symantec's Backup Exec. It should take about 30 minutes. Tevita Tatafu will bring it by then. It's about lunchtime. Can you take a short break?"&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Well... it is a little early for lunch, but that should work."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"Alright Mitch. Anything else?"&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"No... I just hope the backup had all my files on it."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
"It should."&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;"Thanks."&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
She leaned back as she hung her headset by the phone. "Tevita?"&lt;br /&gt;
&lt;p /&gt;
He swung out of his cube, a huge smile on his face. "Mr. Cavanaugh having problems?"&lt;br /&gt;
&lt;p /&gt;
"Yeah," she responded.&lt;br /&gt;
&lt;p /&gt;
"He's such a joy. Did you know he was the one who got impatient waiting in line at the vending machine so he ran to the nearest Dunkin Donuts, opening the door fast enough to knock Edgar flat on his back?"&lt;br /&gt;
&lt;p /&gt;
"You be nice," scolded Jessica with a stern look. "He may have anxiety issues, but he's a spot on accountant."&lt;br /&gt;
&lt;p /&gt;
Tevita laughed richly. "Spot on, eh? And what do you know about Accounting?"&lt;br /&gt;
&lt;p /&gt;
"I got a Masters from University of Chicago's Graduate School of Business, in Accounting."&lt;br /&gt;
&lt;p /&gt;
"You did?"&lt;br /&gt;
&lt;p /&gt;
"Yes. Now don't make me a liar and get that machine to Mitch &amp;lsquo;pronto'."&lt;br /&gt;
&lt;p /&gt;
Tevita laughed, but got up and headed to the equipment room. Jessica sorted through her email. She wanted to clear out her inbox but only halfway through the process Tevita returned, no longer smiling. His mouth bent down in a frown she rarely saw, and usually only when he was about to explode with anger. His eyes didn't seethe, but looked down at a computer in his hands. He sat down and rolled his chair over towards her cube.&lt;br /&gt;
&lt;p /&gt;
"It really is missing the hard drive," he said, expertly using the buttons on the side to open the case. He pointed to an empty bay. "It should be in here, but... well... the IDE cable was cut, right here. Seems stupid, since they had to unscrew the drive, but..."&lt;br /&gt;
&lt;p /&gt;
She stared at the empty bay. "Someone stole his hard drive?"&lt;br /&gt;
&lt;p /&gt;
Tevita nodded. "It looks that way. Mitch said he only left to take a restroom break, and when he came back the system was off and wouldn't boot."&lt;br /&gt;
&lt;p /&gt;
"This isn't good..." Jessica started to say.&lt;br /&gt;
&lt;p /&gt;
"Guys!" Bobby said loudly, his voice piercing through the area like a gunshot. They both stood up, staring at the gangly developer loping towards them from the door to the server room.&lt;br /&gt;
&lt;p /&gt;
"The sky must be falling," Tevita said, but despite the amusement in his voice his mouth only twitched once in an upward smile.&lt;br /&gt;
&lt;p /&gt;
"What's wrong?" Jessica asked.&lt;br /&gt;
&lt;p /&gt;
Bobby took a deep breath. "It's a ninja. I swear by my grandma's heirloom earrings that a ninja just showed up in the server room!"&lt;br /&gt;
&lt;p /&gt;
"A &lt;i&gt;ninja!!?&lt;/i&gt;" Jessica exclaimed.&lt;br /&gt;
&lt;p /&gt;
Tevita looked down a the computer he held. "Bobby, that's not funny..."&lt;br /&gt;
&lt;p /&gt;
Bobby threw his hands up. "You know I don't have an imagination, or much of a sense of humor. Didn't you used to call me Cardboard Boy?"&lt;br /&gt;
&lt;p /&gt;
"Yeah, but I stopped after you randomly locked out my user account at the worst possible moments..."&lt;br /&gt;
&lt;p /&gt;
"I'm not kidding."&lt;br /&gt;
&lt;p /&gt;
Jessica, feeling like she'd just stepped off a rollercoaster, reached out and put a hand on the wall. "Bobby, you mean to tell me there's a ninja loose in the building?"&lt;br /&gt;
&lt;p /&gt;
"Well.. no. He's lying unconscious in the server room."&lt;br /&gt;
&lt;p /&gt;
Tevita gave her a quick look, then bee-lined towards the door to the server room. Jessica wanted to run the other way, but Bobby gave her a helpful shove on the back towards the room. She glanced behind at him, and he blushed.&lt;br /&gt;
&lt;p /&gt;
"Sorry, but the more witnesses the better."&lt;br /&gt;
&lt;p /&gt;
The figure sprawled out on the floor clutched a hard drive in his back-gloved hands. He didn't look like a real ninja, but a black ski mask that looked similar to a ninja wrap covered his face. A goose-egg on his forehead the size of a golf ball, halfway hidden by the mask, seemed to say loudly why he wasn't conscious. Jessica found herself staring, her mouth hanging open and her hand moving up to cover it.&lt;br /&gt;
&lt;p /&gt;
"Oh my gosh," she said, her voice embarrassingly high-pitched. Her heart hammered in her chest as if she'd just jumped off a cliff&lt;br /&gt;
&lt;p /&gt;
Tevita gave Bobby a searching look. "Do you know martial arts or something?" he asked.&lt;br /&gt;
&lt;p /&gt;
"No. I thought I heard something while I was bringing back the two new demo laptops, so I went to check it out. When I saw him, I just reacted."&lt;br /&gt;
&lt;p /&gt;
"What did you do?"&lt;br /&gt;
&lt;p /&gt;
"Well... I had a MacBook Air in my left hand, and a Panasonic Toughbook in the right. The MacBook might be thin enough to decapitate a ninja, but more likely it would have bounced off his skull without slowing him down, so I threw the Toughbook."&lt;br /&gt;
&lt;p /&gt;
Tevita reached out with his toe and nudged the intruder.&lt;br /&gt;
&lt;p /&gt;
"We should leave and call the police," Jessica said, edging towards the door.&lt;br /&gt;
&lt;p /&gt;
"He's out cold," Tevita said, reaching down to pick up the Toughbook. The screen gleamed beautifully, no sign of damage despite being used as a blunt weapon. "Too bad these aren't vPro yet," he said.&lt;br /&gt;
&lt;p /&gt;
"I called the police," Bobby said. "They should be here soon."&lt;br /&gt;
&lt;p /&gt;
The next half-hour moved as if in a dream. Jessica felt like she'd stepped out of the real world and into some crazy movie. Slowly the facts of the intruder came to light, and like wiping away the mist on a foggy window things didn't seem as ridiculous as they first seemed.&lt;br /&gt;
&lt;p /&gt;
The man had been hired to steal a specific hard drive. He was fully cooperative with police, apologetic for getting caught and worrying everyone. He indicated he wore the mask not as an intimidation method, but to remain incognito to security cameras. The policy cuffed him and off he went, leaving everyone standing there in disbelief.&lt;br /&gt;
&lt;p /&gt;
"Is that Mitch's hard drive?" she finally asked Tevita, who had retrieved the hard drive the "ninja" held.&lt;br /&gt;
&lt;p /&gt;
Tevita pointed to connector of a cut IDE cable sticking out the back. "It looks like it..."&lt;br /&gt;
&lt;p /&gt;
Bobby took the drive, hefting it, his small eyes squinting. "No, this is a RAID drive. He &amp;lsquo;raided' a server..."&lt;br /&gt;
&lt;p /&gt;
Jessica stared at him as he chuckled. Tevita stared for a moment, and broke into a wide grin.&lt;br /&gt;
&lt;p /&gt;
"And you say you have no sense of humor," he said with a laugh.&lt;br /&gt;
&lt;p /&gt;
"My Dad told me puns don't count," Bobby responded.&lt;br /&gt;
&lt;p /&gt;
"What about the data on Mitch's hard drive?" Jessica inquired. "I know he had confidential, sensitive information on it."&lt;br /&gt;
&lt;p /&gt;
Bobby shrugged. "Nothing we can do about it unless we can find it. It wouldn't be the first time."&lt;br /&gt;
&lt;p /&gt;
She shook her head. "Too bad vPro doesn't have disk encryption yet. I know they're working on it."&lt;br /&gt;
&lt;p /&gt;
Bobby's head perked up. "vPro with disk encryption? Nice."&lt;br /&gt;
&lt;p /&gt;
The receptionist motioned to Jessica, and she walked over.&lt;br /&gt;
&lt;p /&gt;
"Mr. Johnson has called a meeting in the executive briefing room," she explained, a phone held between her ear and her raised shoulder. "He says it's urgent, but not to worry."&lt;br /&gt;
&lt;p /&gt;
"Not to worry," she echoed, feeling a surreal sense of amusement at the statement. "Right."&lt;br /&gt;
&lt;p /&gt;
She rounded up Tevita and Bobby and they headed upstairs. The executive briefing room flooded with light, with the impeccable CEO standing by the floor to ceiling window showing the bottom half of the skyline to downtown Boston. He smiled casually, his hands clasped behind his back. When they'd all entered and sat down, he turned around, his smiling increasing.&lt;br /&gt;
&lt;p /&gt;
"The mighty defenders arrive," he said. "I had a call from Mitch Cavanaugh concerning your ability to quickly resolve the theft of his hard drive. I commend you on a lightning-fast response. I can tell by your expressions that you're a bit shaken."&lt;br /&gt;
&lt;p /&gt;
He paused, the smile abating. "Let me assure you that we are permanently stepping up our security. I blame myself for not taking steps against blatant thievery. I guess I'd hoped my former colleague had gotten past that type of criminality."&lt;br /&gt;
&lt;p /&gt;
Bobby raised his hand, and Mr. Johnson gestured at him. He cleared his throat, folding his skinny arms.&lt;br /&gt;
&lt;p /&gt;
"So don't we have enough evident now to get the police involved?"&lt;br /&gt;
&lt;p /&gt;
Mr. Johnson shook his head. "No, and even with the thief in hand I doubt they'll be able to link this to New Nifty Networks. For all we know this isn't related to them, though our situation and the probability point in that direction. No, we won't be making any effort to link the thief with Nifty. Your job is to continue tightening our security.&lt;br /&gt;
&lt;p /&gt;
"First, let me commend you, Tevita, for your mastery of providing mirror systems to people when theft occurs. Second, I commend you, Bobby, for always delivering when issues arrive. Lastly, I commend you, Jessica, for your insistence on vPro. I know Edgar and others have given you are hard time about it, but it seems you prove it's worth daily."&lt;br /&gt;
&lt;p /&gt;
"Thank you," she said.&lt;br /&gt;
&lt;p /&gt;
"Our next step is to find out if any other systems have had their hard drives stolen. I'll leave this task in your capable hands. If you have any questions or concerns, please come see me in my office."&lt;br /&gt;
&lt;p /&gt;
As quickly as the meeting started, it ended. &lt;br /&gt;
&lt;p /&gt;
When they reached their cube area, Tevita didn't sit down at his, but followed her into hers. He stared at the Altiris Console idling on her screen, his arms folded and his expression pinched in thought. She sat down, eyeing him, as she reached for her keyboard.&lt;br /&gt;
"Let me guess," Tevita said, "you already have a plan?"&lt;br /&gt;
&lt;p /&gt;
She let her hands fall into her lap. "Well... yeah. It shouldn't difficult to find out which systems no longer have HDDs even if the systems have been off for a while. I just..."&lt;br /&gt;
&lt;p /&gt;
Her voice faded away. She stared at Tevita, trying to sort through her emotions.&lt;br /&gt;
&lt;p /&gt;
"You're freaked," Tevita offered.&lt;br /&gt;
&lt;p /&gt;
"No... well... yeah. I kind of am. Cyber attacks are one thing, but Bobby's ninja..."&lt;br /&gt;
&lt;p /&gt;
Tevita retrieved his chair from his cube, sitting down and leaning back at the entrance of her cube. "With computers thieves usually only break into places for the hardware. Some of the servers Bobby runs cost more than a new BMW. Stealing the hard drives means they're after data. It's really no different, except we're using software to block software attacks, and we use guards, locks, and other such things for the hardware attacks. You heard Johnson. I don't think you have to worry."&lt;br /&gt;
&lt;p /&gt;
She sighed. "We should get occupational hazard pay. I'll get over it, though I may bring pepper spray tomorrow."&lt;br /&gt;
&lt;p /&gt;
"That'll work."&lt;br /&gt;
&lt;p /&gt;
She cracked her knuckles by clasping her fingers and pushing her arms out. "Let's get into this. First off, we can't rely on Inventory Solution to know if the hard drive is there or not, since the OS obviously has to be up and running to get an updated Inventory. We might be able to use the Altiris Agent's last check-in time to note those systems that are no longer reporting, but that won't tell us if those machines are simply off or something similar."&lt;br /&gt;
&lt;p /&gt;
Tevita nodded. "Fun. Without the hard drive we have no manageability capability."&lt;br /&gt;
&lt;p /&gt;
"Except for the one thing that runs outside of the hard drive."&lt;br /&gt;
&lt;p /&gt;
"Intel vPro."&lt;br /&gt;
&lt;p /&gt;
"Exactly. All capabilities are still available even when the hard drive's been yanked."&lt;br /&gt;
&lt;p /&gt;
"So we can use RTSM to remote into those systems not responding in Altiris using Serial-Over-LAN to see if the hard drive is there, like you did for Mitch."&lt;br /&gt;
&lt;p /&gt;
Jessica nodded, smiling. "That would work, but I have a faster, much easier way."&lt;br /&gt;
&lt;p /&gt;
Tevita rolled closer as she put her hand on the mouse and started using the Altiris Console, his eyes focused on the screen. "I like easy," he said.&lt;br /&gt;
&lt;p /&gt;
She browsed under Manage and clicked on Jobs. When the left-pane tree loaded, she browsed under Tasks and Jobs, Server Tasks, Real-Time Console Infrastructure, and clicked on &amp;lsquo;Get Intel&amp;reg; AMT Inventory'. She clicked the Run Now button.&lt;br /&gt;
&lt;p /&gt;
On the resulting window that popped up she gave the Run name: Ninja stolen hard drive, and clicked on the &amp;lsquo;Select computers' link. Within the &amp;lsquo;Select Computers' dialog in the left-most pane, she browsed in the tree from Collections, Out of Band Management, Provisioning, and double-clicked on &amp;lsquo;Provisioned Intel&amp;reg; AMT Computers. The middle pane showed a list of all vPro capable systems in the environment, and the right-most pane showed the Provisioned collection she'd selected. She clicked OK. She then clicked the Run Now button.&lt;br /&gt;
&lt;p /&gt;
"That's it," she said, leaning back. "In the next minute or two we should have inventory from all vPro capable systems."&lt;br /&gt;
&lt;p /&gt;
The Tongan shook his head. "You're going to outsmart us all out of a job," he said.&lt;br /&gt;
&lt;p /&gt;
She raised an eyebrow at him. "Are you kidding? We might, &lt;i&gt;just might&lt;/i&gt;, get to all the stuff on our plates we normally leave forever on the backburner."&lt;br /&gt;
&lt;p /&gt;
She browsed in the Altiris Console under View, Reports, Incident Management, Real-Time Console Infrastructure, and selected Intel&amp;reg; AMT Hardware Inventory. When the report home page loaded, she clicked the Run this report link. For the parameters she left &amp;lsquo;System' to &lt;strike&gt;Any&lt;/strike&gt;, and changed &amp;lsquo;Hardware Type' to &amp;lsquo;Media'. She clicked the &amp;lsquo;Refresh' button to load the report.&lt;br /&gt;
&lt;p /&gt;
"Okay, this shows us all systems that have a hard drive reported with AMT Inventory. We could manually compare the list, but why not create a new report that shows us systems that do not have anything in the Media table?"&lt;br /&gt;
&lt;p /&gt;
She right-clicked on the &amp;lsquo;Real-Time Console Infrastructure' folder and choose New, Report. She gave it the name: Intel vPro Computers Without a Hard Drive. She choose &amp;lsquo;Enter SQL Directly' and then rolled back from her desk.&lt;br /&gt;
&lt;p /&gt;
"Alright SQL guru, I'll give you what I need and you can figure out the query."&lt;br /&gt;
&lt;p /&gt;
He scooted around her, reaching for the keyboard. "Alright. Shoot."&lt;br /&gt;
&lt;p /&gt;
"Okay, we need to have a list of all computers that either do not have an entry within the table Inv_AMT_Media_Device. That's it."&lt;br /&gt;
&lt;p /&gt;
"That's it? That's easy enough..."&lt;br /&gt;
&lt;p /&gt;
Tevita entered in the SQL, and saved the report. When they ran it, only two systems showed up. &lt;br /&gt;
&lt;p /&gt;
Jessica looked at the names of the computers. "These are both from accounting, but Joe is in New York doing his accounting work on his laptop, and this other... he's here, but hasn't reported anything yet.&lt;br /&gt;
&lt;p /&gt;
Tevita stood, dragging his chair back to his cube. "I'll take care of these two. Why don't you go home?"&lt;br /&gt;
&lt;p /&gt;
"And leave you here..."&lt;br /&gt;
&lt;p /&gt;
He laughed. "I'll be fine. It's almost five, and you probably want to take a nice relaxing evening trying not to think about thieves and ninjas."&lt;br /&gt;
&lt;p /&gt;
"Thanks for that," she commented dryly, but with no conviction. "Only if you're sure..."&lt;br /&gt;
&lt;p /&gt;
"I'm sure. I'll see you tomorrow."&lt;br /&gt;
&lt;p /&gt;
"Thanks. Have a good evening."&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;End Part III&lt;/h2&gt;
Recognizing the need for better physical security, and using vPro to minimize the effects of theft, the IT team continue to rise to meet the challenges facing them.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">task_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">real-time_system_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">ider</category>
      <pubDate>Wed, 02 Jul 2008 22:26:36 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/07/02/altiris-and-intel-vpro-use-cases-part-3-hardware</guid>
      <dc:date>2008-07-02T22:26:36Z</dc:date>
      <clearspace:dateToText>1 month, 4 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/altiris-and-intel-vpro-use-cases-part-3-hardware</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11323</wfw:commentRss>
    </item>
    <item>
      <title>Altiris and Intel vPro Use Cases - Part 2 - Antivirus</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/06/19/altiris-and-intel-vpro-use-cases-part-2-antivirus</link>
      <description>If you have not read Part 1 in this article series, please refer to it as this is a continuation of the story begun there:&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://juice.altiris.com/article/4367/altiris-and-intel-vpro-use-cases-part-1-the-setup"&gt;http://juice.altiris.com/article/4367/altiris-and-intel-vpro-use-cases-part-1-the-setup&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Antivirus is a must for any IT infrastructure. Without it productivity is quickly reduced as viruses run rampant in the environment. Keeping Antivirus installed and up to date is vital to ensure continuity of business services. In Part 2 the IT team for Mighty Modern Marketing is put up to the challenge of protecting their network from viral attacks. Using Symantec End Point Protection, Altiris and the Intel vPro technology, they work to ensure that the viral attack and subsequent virus attempts fall ineffective.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;Mighty Modern Marketing HQ - Boston, Massachusetts&lt;/h2&gt;
The commuter rail stretched out across the Charles River, but Jessica Langley didn't notice. Her eyes remained fixed upon the screen of her smartphone, scrolling through the emails that continued to pour in. The subject lines all contained the same word. Her shoulders hunched, feeling like a tremendous weight settled on them. She closed her eyes briefly, rubbing at them with her left hand, the PDA held forlornly in the right.&lt;br /&gt;
&lt;br /&gt;
When she opened her eyes the word jumped up at her.&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;Virus&lt;/i&gt;.&lt;br /&gt;
&lt;p /&gt;
This wasn't the first time this had happened at Mighty Modern Marketing. Viruses routinely showed up as email links or attachments, and it didn't matter how often she or Tevita sent out stern emails reminding people to leave email attachments and links alone unless they were expecting them. People continued to click that link to see the latest movie trailer, or to run the fun and exciting application their aunt or long-lost friend mysteriously sent them from out of the blue.&lt;br /&gt;
&lt;p /&gt;
This time was worse. She'd painted a large red X on her by pushing the Intel vPro technology, and now it seemed everyone stared at her when anything ill befell the network.&lt;br /&gt;
&lt;p /&gt;
She jumped to her feet the moment the train stopped, snatching up her purse and bolting for the nearest door. As she ran down the platform towards the exit of North Station, others gave her curious looks. She smiled briefly. Normally people ran towards the train to avoid missing it. She often saw them frantically running in high-heels or other dress shoes towards a departing train when the work day was &lt;i&gt;over&lt;/i&gt;. Who wanted to run &lt;i&gt;into&lt;/i&gt; work?&lt;br /&gt;
&lt;p /&gt;
As she staggered into the main lobby at work, glad for the cool air that greeted her, she vowed to start exercising. She hurried through the building.&lt;br /&gt;
&lt;p /&gt;
"I'm glad you're here early," Tevita said in his deep voice as she fell into her chair. "We're in trouble."&lt;br /&gt;
&lt;p /&gt;
"I noticed," she said in-between deep breaths. "What's the situation?"&lt;br /&gt;
&lt;p /&gt;
"I'm not sure, but somehow a virus was planted on a new system as it came online. It appears deliberate."&lt;br /&gt;
&lt;p /&gt;
"But... we have Symantec End Point Protection (SEP). It should keep everything out..."&lt;br /&gt;
&lt;p /&gt;
Tevita smiled, though his eyes shifted to his own monitor, his shoulders shrugging uncomfortably. "Yes... about that. You see, the base image hasn't been updated yet to include that..."&lt;br /&gt;
&lt;p /&gt;
Jessica stared at him.&lt;br /&gt;
&lt;p /&gt;
He waved a hand at her. "I know, no need to look at me like that. That's what I've been doing; recreating the image so it's there from the get-go."&lt;br /&gt;
&lt;p /&gt;
She tried not to groan. "So how widespread is it?"&lt;br /&gt;
&lt;p /&gt;
He laughed, though no humor made it into his tones. "All over the place. They used a vulnerability in one of Bobby's applets to spread it. Of course the first thing it did was disable the antivirus. If SEP had been installed it has protection against... Anyway, those systems without SEP are all hit."&lt;br /&gt;
&lt;p /&gt;
Tevita's eyes glanced up, and widened. Jessica whirled to see Bobby walking up, his hands shoved in his jean pockets. He stared at the floor, his mouth moving as if he counted his steps.&lt;br /&gt;
&lt;p /&gt;
"Bobby?" she inquired.&lt;br /&gt;
&lt;p /&gt;
He looked up, looking like a boy lost out in the desert.&lt;br /&gt;
&lt;p /&gt;
"It got through my firewall!" he exclaimed, extracting his hands so he could ball his fingers into fists. "It shouldn't have been able to do that. I can't even use IM."&lt;br /&gt;
&lt;p /&gt;
Tevita gestured to an empty chair. "Have a seat."&lt;br /&gt;
&lt;p /&gt;
Bobby slumped into the chair. "Whoever sent us this thing knew what they were doing," he said with a scowl. "The cursed thing used UNC to move about the network. Only someone with intimate knowledge of our network could do that. It has to be New Nifty Networks!"&lt;br /&gt;
&lt;p /&gt;
"Do you really think...?" Tevita began.&lt;br /&gt;
&lt;p /&gt;
"Bobby," Jessica said quickly. "Have you fixed the vulnerability?"&lt;br /&gt;
&lt;p /&gt;
"How can I?" he lamented. "It jumped from computer to computer, and with mine infected I quickly turned it off. I need your to help me get that virus off so I can patch the applet."&lt;br /&gt;
&lt;p /&gt;
Tevita smiled. "You actually walked over here."&lt;br /&gt;
&lt;p /&gt;
Bobby looked up, his frown deepening. "Yeah? So?"&lt;br /&gt;
&lt;p /&gt;
"It's unprecedented... You usually stay in your cave, even during power outages. Does it make you nervous to enter the world of real people?"&lt;br /&gt;
&lt;p /&gt;
A flush bloomed on Bobby's sunken cheeks. "Not everyone's as social as you."&lt;br /&gt;
&lt;p /&gt;
"You should stop by more often so..."&lt;br /&gt;
&lt;p /&gt;
"So you can ridicule me?" he retorted.&lt;br /&gt;
&lt;p /&gt;
"Guys," Jessica said, rolling her eyes. "Focus here. Bobby, do you have one of the new vPro systems?"&lt;br /&gt;
&lt;p /&gt;
"Yes, of course," he responded, "I always get the latest hardware from procurement."&lt;br /&gt;
&lt;p /&gt;
"Hey, why don't I see any of it?" Tevita blurted.&lt;br /&gt;
&lt;p /&gt;
Jessica ignored him. "Good," she responded to Bobby as she turned back to her computer. She launched the Altiris Console. "If you have one, it should already be provisioned. Let's check the All Provisioned Computers collection... is this yours?"&lt;br /&gt;
&lt;p /&gt;
"No, my computer is named Superman."&lt;br /&gt;
&lt;p /&gt;
Tevita laughed, and Bobby managed to turn an even more alarming shade of red. Jessica kept her expression passive despite the twitch in her lips from a potential laugh. The computer name Superman showed in the list, and she double-clicked on it. She clicked on the Real-Time tab, entered her credentials, and loaded the Hardware Management page under the Real-Time System Manager, Administrative Tasks folders.&lt;br /&gt;
&lt;p /&gt;
"I have a boot ISO of Symantec's Antivirus scan," Jessica explained as the hardware management page loaded. "I'll just turn on your machine but use IDE Redirect (IDER) to load the antivirus disk. We'll wipe the virus, and turn the system off."&lt;br /&gt;
&lt;p /&gt;
"That's great," Bobby said as he shrugged his bony shoulders," except the minute you bring it back up the virus will propagate again."&lt;br /&gt;
&lt;p /&gt;
Jessica smiled. "Not if I invoke a Network Filter."&lt;br /&gt;
&lt;p /&gt;
"What's that?" Tevita asked, as if on cue.&lt;br /&gt;
&lt;p /&gt;
"Tevita, we've covered this. It's the Intel System Defense. You know, block all traffic except to certain ports and IP Addresses. If you want to read up on it I'll email you the URL. (&lt;a class="jive-link-external" href="http://69.93.2.147/article/2645/hold-mf-utilizing-intel-vpro-amt-technology-task-server-part-5-system-defense-tasks)"&gt;http://69.93.2.147/article/2645/hold-mf-utilizing-intel-vpro-amt-technology-task-server-part-5-system-defense-tasks)&lt;/a&gt;."&lt;br /&gt;
&lt;p /&gt;
"System Defense!" Bobby exclaimed. "I read up on that technology. I created a script that provides a text interface where you can specify which ports you want to allow. I call the API's provided by Intel's SDK. It's great stuff."&lt;br /&gt;
&lt;p /&gt;
"RTSM and Task Server already have it configured to only use communication to them," Jessica said, trying not to smile.&lt;br /&gt;
&lt;p /&gt;
"Oh." Bobby cleared his throat as he pushed himself up onto his feet. "That sounds good. Do you need me to stick around...?"&lt;br /&gt;
&lt;p /&gt;
She gave him a grin. "Just for a minute while I do this."&lt;br /&gt;
&lt;p /&gt;
Bobby sat back down, but leaned forward, staring at her monitor. Tevita slid over, looking on with interest. She said a quick silent prayer that it would all work like she theorized it would.&lt;br /&gt;
&lt;p /&gt;
She choose the &amp;lsquo;Power on' radial option, and under the Redirection options checked the &amp;lsquo;Perform boot from' checkbox. She also checked the &amp;lsquo;Display task progress and remotely control computer' option. Under the device drop down she left it at CD image, and then click &amp;lsquo;browse' and located the Symantec ISO. She lastly clicked &amp;lsquo;Run Task Now'.&lt;br /&gt;
&lt;p /&gt;
A new window popped up, showing the computer boot. It loaded the CD and a textual menu showed up giving her scan options. She initiated the scan.&lt;br /&gt;
&lt;p /&gt;
"Looks like it's working," Tevita said.&lt;br /&gt;
&lt;p /&gt;
Bobby nodded. "I had my doubts since I've been unable to ever get Wake-On-LAN to work across my router..."&lt;br /&gt;
&lt;p /&gt;
"Wake-On-LAN packets don't get by any of our switches are routers," the Tongan responded. "I believe you're the one who recommended the network security scheme we use."&lt;br /&gt;
&lt;p /&gt;
"I know, but Altiris did have an Altiris Agent mechanism to try and deal with it, but I couldn't get it to work in my environment. This vPro stuff sure made that easy. I didn't have to touch the router."&lt;br /&gt;
&lt;p /&gt;
"That's the point," Jessica said with just a hint of exasperation in her voice. "Were both of you sleeping when I gave my presentation on vPro last month?"&lt;br /&gt;
&lt;p /&gt;
Tevita smiled, tugging at his collar. "Have I ever mentioned I don't like PowerPoint?"&lt;br /&gt;
&lt;p /&gt;
"Only twice daily. But I showed demos... oh who am I kidding? That's the last time I supply lunch before a presentation."&lt;br /&gt;
&lt;p /&gt;
The two men exchanged glances with sheepish grins, and then focused back on the screen. She looked back to the scan. It finished quickly, showing the virus as detected and quarantined. She closed the remote window and clicked on the Network Filtering node under Administrative Tasks in the Real-Time Console. She checked the &amp;lsquo;Override default solution settings' checkbox and changed the radial selection to &amp;lsquo;Filter network traffic other than to and from the Notification Server'. She clicked Apply. When the page finished refreshing it contained the message, "Machine was successfully moved into quarantine".&lt;br /&gt;
&lt;p /&gt;
"Alright Bobby. I'll use the Power Control to boot your machine up so you can Patch your applet and install SEP. You head back and get it done ASAP. Once it's patched I'm going to mass-remediate all the vPro systems doing the same actions we just did except on a mass scale with Task Server."&lt;br /&gt;
&lt;p /&gt;
Bobby jumped to his feet. "Sounds good. IM me if you need anything..."&lt;br /&gt;
&lt;p /&gt;
"Except IM won't make it through the Network Filter," she responded dryly.&lt;br /&gt;
&lt;p /&gt;
"Ah... yes. Well... you know where I am."&lt;br /&gt;
&lt;p /&gt;
"Quick question, how long will it take you?"&lt;br /&gt;
&lt;p /&gt;
"Less than an hour."&lt;br /&gt;
&lt;p /&gt;
As Bobby walked away Tevita smiled hugely, some of his natural humor finally flowing back into his features. "He's a real gem."&lt;br /&gt;
&lt;p /&gt;
"You should cut him some slack," she scolded.&lt;br /&gt;
&lt;p /&gt;
"Bobby? I'm holding back, really I am. It's just too much of a temptation. He's classic nerd. But he is a master at what he does, so I'll be sure to keep it friendly."&lt;br /&gt;
&lt;p /&gt;
"I'm reassured," she said, rolling her eyes for the third time that day. She then gave him a sly smile.&lt;br /&gt;
&lt;p /&gt;
"What?" he said, his smile drooping. "You have that look."&lt;br /&gt;
&lt;p /&gt;
"Regardless of blame, even though you should have updated the image weeks ago to include Symantec Endpoint Protection so I blame you for this mess, I need you to create a CD out of the Antivirus boot ISO and load SEP on a flash drive so you can manually remediate those systems without vPro."&lt;br /&gt;
&lt;p /&gt;
Tevita swallowed. "Hey, we've had a pretty busy workload..."&lt;br /&gt;
&lt;p /&gt;
She softened her look. "I know, sorry. Anyway... when you get to each system, yank the network cable, use the ISO to clean the virus, then load SEP, and then put the cable back in. I'd even suggest making several copies so you can do a handful at a time. And here's a printout of all non-vPro systems."&lt;br /&gt;
&lt;p /&gt;
Tevita took the printout and nodded. "I'm on it."&lt;br /&gt;
&lt;p /&gt;
Jessica focused back on the Altiris Console after Tevita left clutching ten copies of the ISO and SEP installer. She browsed under Manage, Jobs, Tasks and Jobs, right-clicked on Jobs, and choose &amp;lsquo;New Folder'. She right-clicked on the new folder and choose &amp;lsquo;New &amp;gt; Task/Job'. In the resulting window she choose &amp;lsquo;Server Job' under the &amp;lsquo;Jobs' folder. The first element popped up a message from a VB script stating that an emergency procedure would fire in 60 seconds, and instructing the user to save all data. Her second task was a &amp;lsquo;Boot Redirection Task' that booted up a modified ISO that automatically ran the scan and took any appropriate actions against detected threats. The third task invoked the Network Filter, allowing only NS and Task Server communication capability with the system. For the fourth Task she located the SEP install Tevita had made with Altiris Software Delivery Solution and put it into a Task Server Deliver Software Task. Finally she created the fifth and sixth tasks that removed the filter and invoked a reboot to finish the process.&lt;br /&gt;
&lt;p /&gt;
She saved the job and selected her own system to test it.&lt;br /&gt;
&lt;p /&gt;
"Mrs. Langley," a familiar voice prompted. Normally she caught movement in the mirror mounted on her flat panel monitor when someone walked up to her, but she'd been so focused that this time she started almost violently in surprise, whirling around in her chair.&lt;br /&gt;
&lt;p /&gt;
Edgar Watts stood behind her, his hands conspicuously empty of printouts. Her first impulse was to point to her screen and tell him she had a plan with vPro to take care of the virus in a timely manner.&lt;br /&gt;
&lt;p /&gt;
She rose to her feet, trying to place a polite and not strained smile on her face. "Hello Mr. Watts."&lt;br /&gt;
&lt;p /&gt;
"Since my computer is down, I've been using my laptop to research the impact of viruses to corporations, specifically impacts to finances."&lt;br /&gt;
&lt;p /&gt;
He frowned, briefly rubbing a forefinger along his jaw. He didn't immediately continue, his vexed expression seeming to say he was seeing those numbers again and loathing what he saw.&lt;br /&gt;
&lt;p /&gt;
"We're working on it," she said, trying not to sound defensive.&lt;br /&gt;
&lt;p /&gt;
"I know," he responded. "I'm astounded at the amount of this company's hard-heard cash flow flowing down the drain."&lt;br /&gt;
&lt;p /&gt;
"We'll have your and all vPro enabled systems up within the hour," she said, forcing that smile to remain on her face."&lt;br /&gt;
&lt;p /&gt;
"One hour?" he responded, looking down at his watch as his brow drew low over his eyes, almost like a thundercloud.&lt;br /&gt;
&lt;p /&gt;
She braced for some kind of outburst, feeling sour in the pit of her stomach. It seemed like her stomach wanted to remain clenched, and she couldn't relax the muscles in her shoulders. What more could she do? She often woke in the middle of the night, her sleep-clouded mind immediately whirling through all the issues she needed to address immediately. She needed to prove vPro, identify and eliminate any threat from their nefarious competitor, keep Edgar's expense-cutting knives away from her department, and still find enough time to enjoy time with her husband. Lying awake at night, trying to will herself to sleep, got old fast. Two days ago her husband had recommended quitting.&lt;br /&gt;
&lt;p /&gt;
That seemed wrong. She'd never given up on anything in the past, and she didn't want to give up on this now, especially when all of Mighty Modern Marketing needed her at this critical time.&lt;br /&gt;
&lt;p /&gt;
When Edgar looked back up from his watch he smiled, a rare sight that stilled her thoughts, her breath catching in her throat.&lt;br /&gt;
&lt;p /&gt;
"All vPro capable systems, you say?" he asked.&lt;br /&gt;
&lt;p /&gt;
"Yes sir," she responded after a moment of stunned silence.&lt;br /&gt;
&lt;p /&gt;
"I came down to wish you luck, but perhaps you don't need that luck after all. Good day, Jessica."&lt;br /&gt;
&lt;p /&gt;
He turned around and walked away, and she stood and stared at him. She almost chuckled, but she still felt too emotionally invested and she just might break down and tear up. She slowly sat back down, staring at the Altiris Console. With renewed vigor she tested her job, made a few tweaks to the command-line of the rollout job, and then brought up a Run Now window, selecting All Provisioned Systems. Her mouse hovered over the Run Now button.&lt;br /&gt;
&lt;p /&gt;
"Come on Bobby," she whispered. The few minutes before the IM popped up declaring "Applet is patched" seemed like an eternity.&lt;br /&gt;
&lt;p /&gt;
She clicked the Run Now button.&lt;br /&gt;
&lt;p /&gt;
She got up and took a quick water break, grabbing a drink and throwing it down as if a shot in a drinking contest. She didn't want to return to her desk. What if it failed on most systems, especially the executive team's? What if she hadn't accounted for different hardware platforms in her job? What if?&lt;br /&gt;
&lt;p /&gt;
She squared her shoulders, throwing off the &amp;lsquo;what if' game. She walked resolutely back to her desk and sat down, refreshing the job.&lt;br /&gt;
&lt;p /&gt;
Ninety percent success rate brought a smile to her lips.&lt;br /&gt;
&lt;p /&gt;
For the next few hours she used RTSM to connect to and patch those systems where the Task Server job failed for whatever reason. Most she could figure out the issue by using RTSM, aided by the article, &lt;a class="jive-link-external" href="http://69.93.2.147/article/4075/troubleshooting-altiris-manageability-toolkit-vpro-technology-part-5-real-time-console-"&gt;http://69.93.2.147/article/4075/troubleshooting-altiris-manageability-toolkit-vpro-technology-part-5-real-time-console-&lt;/a&gt;, since RTCI was the component that executed most Task Server and RTSM commands against AMT.&lt;br /&gt;
&lt;p /&gt;
Toward the end of the business day she leaned back. All vPro capable systems, a good 75% of the environment, was patched. Just as she shut down her computer Tevita showed up. His natural good humor managed to put a smile on his face. His long-sleeved dress shirt had the sleeves rolled up, his tie loose and top button of his collar undone. Sweat glistened on his forehead, remnants of computer dust bunnies streaked on his hands and forearms.&lt;br /&gt;
&lt;p /&gt;
"Hi!" she said, unable to keep from smiling in amusement at him.&lt;br /&gt;
&lt;p /&gt;
"Let me guess," he said, his smile twisting a little, "you've managed to patch all vPro systems."&lt;br /&gt;
&lt;p /&gt;
"Yes," she responded, putting her purse back down on her desk. "How's the other systems coming?"&lt;br /&gt;
&lt;p /&gt;
"I'm... uh... half done."&lt;br /&gt;
&lt;p /&gt;
She nodded, picking up her phone. "Tevita, give me just a moment. Hi, Rob? I'm fine, though it looks like I'll be here a while. It's mostly under control, but we have a few more systems to fix. I know, I'm sorry. I'll see you later tonight, honey. Love you too, bye."&lt;br /&gt;
&lt;p /&gt;
"What are you doing?" Tevita asked, frowning.&lt;br /&gt;
&lt;p /&gt;
"We need to finish up, right?"&lt;br /&gt;
&lt;p /&gt;
"Well... yes. But you don't really have to..."&lt;br /&gt;
&lt;p /&gt;
"I'm thinking your wife wants to see you at least some time tonight. I'll take the third floor, you finish up the second, and the last one done has to bring donuts tomorrow."&lt;br /&gt;
&lt;p /&gt;
Tevita looked relieved. "Deal. Thanks, Jessica."&lt;br /&gt;
&lt;p /&gt;
Bobby walked up, a laptop case in his hands. "I'm heading out. Thanks for getting me back up so fast."&lt;br /&gt;
&lt;p /&gt;
Jessica turned to him, her smile growing. "Bobby, we need your help," she said without preamble. "We have a few more systems to remediate..."&lt;br /&gt;
&lt;p /&gt;
Bobby shook his head, his expression tightening. "No way, I have a Halo 3 party..."&lt;br /&gt;
&lt;p /&gt;
"Bobby, you can't abandon us..."&lt;br /&gt;
&lt;p /&gt;
Bobby looked down at the case in his hands. "Ah nuts! You don't know what this does to me. I'll lose my leader spot..."&lt;br /&gt;
&lt;p /&gt;
"You'll make it up," Tevita said confidently. "If we get this done quickly imagine how impressed they'll be when you join late and still take the top spot."&lt;br /&gt;
&lt;p /&gt;
Bobby's stricken look abated. "Yes. Yes, that would be impressive. Ok, I'll help."&lt;br /&gt;
&lt;p /&gt;
Hours later Jessica left the building, running towards North Station to catch one of the late trains home, her shoulders feeling much lighter than when she'd rode in.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;End Part II&lt;/h2&gt;
Having minimized the damage of the first attack, the IT staff will continue to prepare in anticipation of more cyber attacks.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">task_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris_console</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">real_time_system_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <pubDate>Thu, 19 Jun 2008 20:59:44 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/06/19/altiris-and-intel-vpro-use-cases-part-2-antivirus</guid>
      <dc:date>2008-06-19T20:59:44Z</dc:date>
      <clearspace:dateToText>2 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/altiris-and-intel-vpro-use-cases-part-2-antivirus</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11300</wfw:commentRss>
    </item>
    <item>
      <title>Troubleshooting the Altiris Manageability Toolkit for vPro Technology - Part 6 - Real-Time System Manager</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/05/07/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</link>
      <description>&lt;p /&gt;
Formerly known as Web Admin for Windows, Real-Time System Manager provides a powerful set of functions for IT specialists. In part 5 of this article series we covered the main points for Real-Time Console Infrastructure troubleshooting. As a natural extension of RTCI, Real-Time System Manager troubleshooting is covered in this article as part 6. With an emphasis on credentials and connection methods, this article provides information to overcome the most common issues seen when using the Real-Time tab for direct, one-to-one computer interaction.&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;Introduction&lt;/h1&gt;
Real-Time System Manager provides a powerful tool for directly connecting to a system agentlessly with functionality available through WMI and Intel AMT. This article covers the issues associated with general functions seen with both technologies but with emphasis on the AMT functions. The following sections cover areas of troubleshooting:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Connection Issues&lt;/li&gt;
&lt;li&gt;Authentication Issues&lt;/li&gt;
&lt;li&gt;IDE Redirect (IDER)&lt;/li&gt;
&lt;li&gt;Network Filtering&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;h1&gt;Connection Issues&lt;/h1&gt;
Under the current architecture the FQDN is the primary method for connecting and authenticating to AMT on remote systems. If the FQDN the Real-Time tab is using does not resolve in DNS, then AMT connectivity and thus functionality will not be available. FQDN connectivity issues are the number one issues we see with RTSM connections to AMT.&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Invalid FQDN&lt;/h2&gt;
To view what FQDN the Real-Time is using, use the &amp;lsquo;Hardware Management' node in the RTSM tree. The following screenshot shows what AMT is using:&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1382/RTSMfqdn.jpg" alt="RTSMfqdn.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1382/RTSMfqdn.jpg');return false;"/&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
In this example my system is in a workgroup and reported only the hostname as the FQDN, which DNS had no trouble resolving. If this fqdn is not reachable via DNS, we won't be able to connect to the AMT functionality.&lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;NOTE: We use several methods, including IP address, for WMI. WMI functionality may show correctly when AMT is absent in this situation&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Use these steps to see the FQDN is the issue:&lt;br /&gt;
&lt;p /&gt;
&lt;ol&gt;
&lt;li&gt;Open the Real-Time tab for the AMT system you are managing.&lt;/li&gt;
&lt;li&gt;Once the tree loads, open the Real-Time System manager folder, open Administrative Tasks, and click on &amp;lsquo;Hardware Management'.&lt;/li&gt;
&lt;li&gt;Once the page loads, if AMT is missing as an available technology, take note of the name displayed as in the screenshot above.&lt;/li&gt;
&lt;li&gt;Go to Start, Run, type in cmd, and click OK.&lt;/li&gt;
&lt;li&gt;Type in nslookup &amp;lt;name displayed&amp;gt;. In the above example it would read:
&lt;ol&gt;
&lt;li&gt;Nslookup dellvpro&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Can DNS resolve this address? If no, we'll need to fix the issue in one of the following ways.&lt;/li&gt;
&lt;li&gt;FIX DNS and/or the Altiris record: If DNS can be fixed, this is the preferred method. The difficulty is finding out why the Altiris Agent reported the incorrect record. Once DNS is fixed, have the Altiris Agent run Basic Inventory. The table location we pull this out of for management in RTSM is Inv_AeX_AC_Location, column: &lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=Fully+Qualified+Domain+Name"&gt;Fully Qualified Domain Name&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use the &amp;lsquo;Manage' node available in RTSM (see the below screenshot): By putting in the IP address of the system, we'll use the IP to lookup the FQDN and not make any assumptions. &lt;br clear="all" /&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1384/Manageshortcut.JPG" alt="Manageshortcut.JPG" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1384/Manageshortcut.JPG');return false;"/&gt;&lt;/li&gt;
&lt;li&gt;Update the Servers HOSTS or LMHOSTS files to contain the mapping to the invalid name. For example find the LMHOSTS file, edit it and add a line &amp;lt;IP ADDRESS&amp;gt; &amp;lt;FQDN&amp;gt;, as in this example:
&lt;ol&gt;
&lt;li&gt;10.10.10.1 Dellvpro&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;h2&gt;Real-Time unable to connect&lt;/h2&gt;
If WMI and AMT functions are unavailable, you'll get a message when you click on the Real-Time tab indicating that the functionality isn't available. See the following screenshot:&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1383/NoRTSMavailable.jpg" alt="NoRTSMavailable.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1383/NoRTSMavailable.jpg');return false;"/&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;Note: If you use another product such as Dell or HP's plug-ins to this tab, you'll simply not have the &amp;lsquo;Real-Time System Manager' node underneath Real-Time Consoles.&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
The number one reason this occurs is due to a firewall being engaged. Firewalls need to allow AMT traffic through. If a firewall is enabled, use the following details to resolve the AMT issue:&lt;br /&gt;
&lt;p /&gt;
&lt;ol&gt;
&lt;li&gt;Create an inclusion in the firewall properties.&lt;/li&gt;
&lt;li&gt;Allow the following ports, based off your environment:
&lt;ol&gt;
&lt;li&gt;16992 - For non-TLS encrypted traffic - if you are not using TLS this is the port that will be used for communication&lt;/li&gt;
&lt;li&gt;16993 - For TLS-enabled, encrypted AMT traffic - If https is required for communication with AMT, this port will be used&lt;/li&gt;
&lt;li&gt;16994 - For a note, AMT provisioning uses this port for sending out the &amp;lsquo;hello' packet during the configuration process - this will be used if you initiate a reprovision from RTSM&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Another options is to disable the firewall when you need to manage the system via RTSM.&lt;/li&gt;
&lt;li&gt;Unfortunately WMI has a known issue with the Windows firewall where the dynamic ports WMI uses after initiation will be blocked. It's a bug in WMI that has been addressed in Vista. Previous Operating Systems do not have a resolution at this time.&lt;/li&gt;
&lt;/ol&gt;
&lt;p /&gt;
&lt;p /&gt;
The other issue we've seen is where the system is simply unavailable for one reason or another. AMT is available if the system is off but still connected to the network, but WMI or if the system is unplugged from power or off the network RTSM obviously cannot function. Verify that the system is available if nothing resolves this issue.&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;Authentication Issues&lt;/h1&gt;
Another common issue concerns authentication to the system via the Real-Time tab. First, let me discuss the methods RTSM uses to authenticate to a target system.&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Authentication Methods&lt;/h2&gt;
&lt;b&gt;Runtime Profile&lt;/b&gt; - The Runtime profile contains he following information:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;All known good credentials used to connect via RTSM to a system&lt;/li&gt;
&lt;li&gt;The Intel SCS AMT password sent to systems when provisioning occurs&lt;/li&gt;
&lt;li&gt;Previously successfully used credentials from past RTSM sessions&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;User-defined Profiles&lt;/b&gt; - Profiles can be created that specifically provide credentials for the four types of technologies:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;WMI digest or Domain account&lt;/li&gt;
&lt;li&gt;AMT digest or Kerberos-authenticated user&lt;/li&gt;
&lt;li&gt;ASF digest or Domain account&lt;/li&gt;
&lt;li&gt;SNMP community strings&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;Manually entered credentials&lt;/b&gt; - When RTSM tries to connect, if the default profile set in the RTCI configuration fails to authenticate, the left-hand tree will still load but each node will prompt the user for credentials. A user can put in an AMT account, Domain user, or digest user that has rights on the target system. When authentication succeeds, these credentials are then stored in the Runtime Profile for the target system.&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Troubleshooting Authentication&lt;/h2&gt;
The following method will help identify issues and offer ways to work-around and solutions. These have been compiled through experience when troubleshooting issues with failed authentication with RTSM.&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;In the Altiris Console browse to View &amp;gt; Solutions &amp;gt; Real-Time Console Infrastructure &amp;gt; Configuration &amp;gt; select Manage Credentials Profiles.&lt;/li&gt;
&lt;li&gt;Where does the green checkmark fall? This is the default profile that will be used when connecting via the Real-Time tab.&lt;/li&gt;
&lt;li&gt;Create a new profile by clicking the blue + on the icon bar in the right-hand pane.&lt;/li&gt;
&lt;li&gt;Under the Intel&amp;reg; AMT tab check the box &amp;lsquo;Enable this technology in the profile'.&lt;/li&gt;
&lt;li&gt;Supply the admin user credentials set when the managed vPro systems were provisioned.&lt;/li&gt;
&lt;li&gt;Under the WMI tab also check the box as above and provide a user that has admin privileges to the target system.&lt;/li&gt;
&lt;li&gt;Give the profile a name and then save it.&lt;/li&gt;
&lt;li&gt;Back at the main screen check the box under the &amp;lsquo;Default' column until the green check-mark uses your new Profile.&lt;/li&gt;
&lt;li&gt;Test to see if this new profile is successful. Note that you'll need to launch IE fresh to use the new settings.&lt;/li&gt;
&lt;li&gt;If it is not, try entering credentials in manually when you hit the system under the Real-Time tab. See the screenshot below for the connection icon to switch between WMI and AMT authentication. If two show in this area, both technologies are available but not authenticated. &lt;br clear="all" /&gt;&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1385/RTSMconnectiontype.jpg" alt="RTSMconnectiontype.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11143-1385/RTSMconnectiontype.jpg');return false;"/&gt;&lt;/li&gt;
&lt;li&gt;In one case we supplied only AMT credentials in the Profile which allowed it to authenticate to AMT while a multiple protocol authentication profile failed.&lt;/li&gt;
&lt;li&gt;Check the collection you are launching Resource Explorer from. Sometimes the identity of the system is incorrect. For AMT you can launch RTSM from the Provisioned collections populated with the Resource Synchronization.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;h1&gt;IDE Redirect (IDER)&lt;/h1&gt;
IDE Redirect allows a system to be remotely booted to a file, drive, or virtual disc. There are a number of potential issues to be aware of when working with IDER in a vPro environment. The below items include well-known issues and their resolutions.&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;Redirection Invalid Parameter&lt;/h2&gt;
When initiating an IDER (IDE Redirect) session to an external source such as an .iso file, the following error appears in the console: &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
Power management operation failed.&lt;br /&gt;
Redirection session start has failed. See logs for more details.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
The Notification Server log shows the following error: &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Log File Name: C:\Program Files\Altiris\Notification Server\Logs\a.log&lt;br /&gt;
Priority: 2&lt;br /&gt;
Date: 3/9/2007 2:51:05 PM&lt;br /&gt;
Tick Count: 10617218&lt;br /&gt;
Host Name: &amp;lt;&amp;gt;&lt;br /&gt;
Process: w3wp.exe (2436)&lt;br /&gt;
Thread ID: 5412&lt;br /&gt;
Module: AltirisNativeHelper.dll&lt;br /&gt;
Source: RTCI.Trace&lt;br /&gt;
Description: RedirectionProvider::StartIDER - RedirectionProvider::StartIDER - IMR_IDEROpenTCPSession: IMR_RES_INVALID_PARAMETER&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
This is caused by Intel's redirection library requiring a correct floppy device to initiate an IDER session (either floppy image or real removable device). Real-Time System Manager 6.2 can work around this. If you put floppy.img file into &lt;i&gt;Program Files\Altiris\RTSM\UIData&lt;/i&gt; folder, then the issue will not occur.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;IDER or SOL Disabled&lt;/h2&gt;
In some instances Intel vPro systems are arriving from the OEM with IDER and SOL disabled in the BIOS. When disabled, neither of these functions work from any management engine, including RTSM. Correcting this oversight is not easy, especially if the OEMs do not offer a solution by a firmware or BIOS update. Use the following method to resolve the issue:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Go to the Support site for the OEM for the systems.&lt;/li&gt;
&lt;li&gt;Browse to the drivers and downloads section for the exact model (note that sometimes the model will differ based on possessing or not possessing vPro technology).&lt;/li&gt;
&lt;li&gt;Check the firmware updates for a new BIOS.&lt;/li&gt;
&lt;li&gt;Check the documentation for any new BIOS versions that include vPro to see if they've corrected this.&lt;/li&gt;
&lt;li&gt;Contact your OEM if they have not and request a status!&lt;/li&gt;
&lt;li&gt;The only other recourse is to develop an update yourself or manually update the settings by visiting the system.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;h1&gt;Conclusion&lt;/h1&gt;
This should account for the most common issues we've seen, and allow you to successfully use RTSM with AMT technology, avoiding those issues.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">centrino_pro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">troubleshoot</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">real-time_system_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtci</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">notification_server</category>
      <pubDate>Wed, 07 May 2008 18:18:23 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/05/07/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</guid>
      <dc:date>2008-05-07T18:18:23Z</dc:date>
      <clearspace:dateToText>3 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/troubleshooting-the-altiris-manageability-toolkit-for-vpro-technology-part-6-realtime-system-manager</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11143</wfw:commentRss>
    </item>
    <item>
      <title>How to Configure Security to add or limit access to the Real-Time tab in RTSM for Intel AMT technology and WMI access</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/04/24/how-to-configure-security-to-add-or-limit-access-to-the-realtime-tab-in-rtsm-for-intel-amt-technology-and-wmi-access</link>
      <description>The ability to provide access to the Real-Time tab of Resource Manager will enable administrators to provide this valuable tool to IT specialists or Helpdesk workers.  Furthermore the ability to configure access to certain functions within the console will allow administrators to grant or restrict what users can do with Real-Time System Manager.  This includes WMI functionality as well as powerful AMT functionality.&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;Introduction&lt;/h1&gt;
&lt;br /&gt;
Your environment will likely have a unique set of requirements on who can access what in Real-Time System Manager.  It can be as simple as two levels of workers, from an administrator to an IT Specialist, to a complex system of access rights in a multi-tiered environment tightly controlled.  No matter the environment, this article provides the details to customize access to the Real-Time tab, including WMI and AMT access rights.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
RTSM contains limited functionality to configure access via WMI.  AMT, on the other hand, can be configured at a function-granular level.  Whether you're simply trying to give users full access to RTSM, or to provide access to only certain functions, this document assists to achieve this.&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;NS Role Security&lt;/h1&gt;
&lt;br /&gt;
The first item that must be enabled is creating a role or modifying an existing role to have rights to Real-Time System Manager at the general level.  Without assignment to such a role, a user cannot gain access to RTSM.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;Overview&lt;/h2&gt;
&lt;br /&gt;
Briefly I'll explain how NS Role and Scope security work together in Notification Server.  Roles give feature access rights.  For example in Software Delivery Solution there's a role object labeled &amp;lsquo;Item Tasks - Software Delivery Wizard'.  The two options allow use of the Simple or Advanced Software Delivery Wizard.  Without this right, the user cannot launch the Software Delivery Wizard, regardless if they have scope rights to the Wizard and Status node in the console.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
Scope security is much like the Windows File-System security model.  In the Altiris Console the left-hand tree can be accessed like the file system, applying security to folders or to nodes, as opposed to folders and files.  Inherence allows security to be inherited from the containing folder, on up the chain until the root node is reached.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;Role Configuration&lt;/h2&gt;
&lt;br /&gt;
The following steps show how to create a user with RTSM permissions.  &lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;In the Altiris Console, browse to View &amp;gt; Configuration &amp;gt; Server Settings &amp;gt; Notification Server Settings &amp;gt; Security Roles.&lt;/li&gt;
&lt;li&gt;Select an existing Role or Right-click on the Security Roles folder and choose to create a new Role.&lt;/li&gt;
&lt;li&gt;Under Privileges, find the following categories and check the indicated option.  After the screenshot the items are details with description of the option: &lt;br clear="all" /&gt; &lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1371/RTSMRole.jpg" alt="RTSMRole.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1371/RTSMRole.jpg');return false;"/&gt;
&lt;ol&gt;
&lt;li&gt;&lt;b&gt;Altiris System Privileges&lt;/b&gt; - &lt;i&gt;Use Real-Time System Management&lt;/i&gt; - This is the ability to use the product at the most basic and general level.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Altiris Console Privileges&lt;/b&gt; - &lt;i&gt;View Resources Tab&lt;/i&gt; - For this example I'm providing the user the ability to see collections so he or she can launch Resource Manager and use the Real-Time tab.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Altiris Console Privileges&lt;/b&gt; - View Tasks Tab - Access to the &amp;lsquo;Manage' node allowing launch of Resource Manager requires this privilege.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Item Tasks - Real-Time System Manager&lt;/b&gt; - &lt;i&gt;Manage&lt;/i&gt; - This is access to the main tree for RTSM.  Most functions are covered by this option.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Item Tasks - Real-Time System&lt;/b&gt; &lt;b&gt;Manager&lt;/b&gt; - &lt;i&gt;Password Reset&lt;/i&gt; - Because of the nature of this function, it has been separated out as a single security role object in Notification Server but belongs to the Real-Time tree.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Item Tasks - Real-Time System Manager&lt;/b&gt; - &lt;i&gt;Port Check&lt;/i&gt; - The Port Check feature is normally accessed as a separate contextual item in the right-click menu, or launch from an icon under the Real-Time tab.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Item Tasks - Real-Time System Manager&lt;/b&gt; - &lt;i&gt;Trace Route&lt;/i&gt; - This is treated in the same way as Port Check.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Item Tasks - Real-Time System Manager&lt;/b&gt; - &lt;i&gt;Hardware Management&lt;/i&gt; - This is one of the objects in the tree that provides basic hardware function, which is greatly extended if the system is Intel vPro capable and Provisioned.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Click the Membership tab.&lt;/li&gt;
&lt;li&gt;Use the blue + icon to add users and/or groups to the Role.  These can be digest users or local computer groups, or Domain users or groups.&lt;/li&gt;
&lt;li&gt;Click Apply to save the Role.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;i&gt;Note: The users will not have access yet to the Altiris Console as the scope-level security has not been set for the new Role.  Complete the below NS Scope Security section to give access to the Altiris Console&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;NS Scope Security&lt;/h1&gt;
&lt;h2&gt;Altiris Console&lt;/h2&gt;
&lt;br /&gt;
For Altiris Console access, scope security must be configured before a Role can access or login to the console.  The security window is the same for any node, be it a folder or otherwise.  The two screenshots below show the security window and the permission selection screens:&lt;br /&gt;
&lt;p /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1372/SecurityProperties.jpg" alt="SecurityProperties.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1372/SecurityProperties.jpg');return false;"/&gt;  &lt;br /&gt;
&lt;p /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1373/ActionPermissions.jpg" alt="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/1373/ActionPermissions.jpg" class="jive-image"  /&gt; &lt;br /&gt;
&lt;p /&gt;
&lt;i&gt;Note: Depending on the object type, the available permissions may differ&lt;/i&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
To allow access to the &amp;lsquo;Manage' Real-Time Console Infrastructure Task, follow these steps:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;In the Altiris Console, browse under View &amp;gt; Tasks &amp;gt; Incident Resolution &amp;gt; Tools.&lt;/li&gt;
&lt;li&gt;Right-click on the node &amp;lsquo;Manage' and choose Properties.&lt;/li&gt;
&lt;li&gt;Click on the Security tab.&lt;/li&gt;
&lt;li&gt;Click the &amp;lsquo;Add' button.&lt;/li&gt;
&lt;li&gt;Select from the list &lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=Role"&gt;Role&lt;/a&gt; &lt;strike&gt;name of your role&lt;/strike&gt; (+ie:+ &lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=Role"&gt;Role&lt;/a&gt; RTSM Workers) and click the &amp;lsquo;Select' button.&lt;/li&gt;
&lt;li&gt;Check the option for &amp;lsquo;Full Control' and click &amp;lsquo;Select'. &lt;br clear="all" /&gt; &lt;i&gt;Note: Full Control does not give the user the ability to delete or otherwise manipulate the Manage node.  This node can only be accessed for the function alone.&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;Click &amp;lsquo;Apply' to save the security changes made.&lt;/li&gt;
&lt;/ol&gt;
&lt;p /&gt;
&lt;p /&gt;
To access Collections so the users of the role can view collections so they can use the RTSM right-click contextual menu options for a listed resource, follow these steps:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;In the Altiris Console, browse to View &amp;gt; Resources &amp;gt; Collections.&lt;/li&gt;
&lt;li&gt;Depending on what collections you want to give the user access to, browse to a containing folder or an individual collection.&lt;/li&gt;
&lt;li&gt;Right-click on the folder or collection and choose Properties.&lt;/li&gt;
&lt;li&gt;Click on the Security tab.&lt;/li&gt;
&lt;li&gt;Click the &amp;lsquo;Add' button.&lt;/li&gt;
&lt;li&gt;Select from the list &lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=Role"&gt;Role&lt;/a&gt; &lt;strike&gt;name of your role&lt;/strike&gt; (+ie:+ &lt;a class="jive-link-adddocument" href="http://communities.intel.com/openport/community-document-picker.jspa?communityID=&amp;subject=Role"&gt;Role&lt;/a&gt; RTSM Workers) and click the &amp;lsquo;Select' button.&lt;/li&gt;
&lt;li&gt;Check the following options:
&lt;ol&gt;
&lt;li&gt;Altiris System Permissions - Read&lt;/li&gt;
&lt;li&gt;Altiris Resource Management Permissions - Read Resource Data&lt;/li&gt;
&lt;li&gt;Altiris Resource Management Permissions - Read Resource Association&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;Click Select, and then click Apply on the permissions window.&lt;/li&gt;
&lt;/ol&gt;
&lt;p /&gt;
&lt;p /&gt;
Now we have allowed the user access to certain parts of the Altiris Console so they can execute Real-Time System Manager on managed systems.  To restrict access to certain parts of the RTSM console, see the previous Role section for what options are available to you.&lt;br /&gt;
&lt;p /&gt;
&lt;h2&gt;AMT Permissions&lt;/h2&gt;
&lt;br /&gt;
RTSM takes advantage of powerful functionality available in Intel vPro, AMT technology.  Once a user has access to RTSM, their user account, if permitted, is used to connect to the remote system by WMI.  An AMT connection can either use Kerberos integration or an inputted digest user when prompted.  The credentials must be specified in the destination system's AMT Profile, otherwise authentication will fail.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
To configure who has rights to AMT, follow these steps:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;In the Altiris Console, browse to View &amp;gt; Solutions &amp;gt; Out of Band Management &amp;gt; Configuration &amp;gt; Provisioning &amp;gt; Configuration Service Settings &amp;gt; Provision Profiles.&lt;/li&gt;
&lt;li&gt;Double-click on an existing profile, or create a new one.&lt;/li&gt;
&lt;li&gt;Click on the ACL tab.&lt;/li&gt;
&lt;li&gt;Click Add to add either a digest user or to use Domain users and groups with Kerberos integration.&lt;/li&gt;
&lt;li&gt;Once a user is inputted, the &amp;lsquo;Realms' section allows or disallows access to different AMT functions.  The boxes that are of importance to RTSM are:
&lt;ol&gt;
&lt;li&gt;Circuit Breaker - Now known as System Defense, or Network Filtering&lt;/li&gt;
&lt;li&gt;Hardware Asset - For power management capabilities&lt;/li&gt;
&lt;li&gt;Redirection - To allow IDE Redirection&lt;/li&gt;
&lt;li&gt;Remote Control - Allows Serial Over LAN (SOL) remote connection&lt;/li&gt;
&lt;li&gt;Event Manager - Allows viewing of AMT logs&lt;/li&gt;
&lt;li&gt;General Info - Allows viewing of AMT data on the system&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;The &amp;lsquo;Access Permission' dropdown should be used to select either Network Access or Any.  The Local Access option gives that user rights to log into the Intel ME locally when the system boots and isn't needed for RTSM function, however if you wish to allow the user to have access to both, choose &amp;lsquo;Any'. &lt;br clear="all" /&gt; &lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1374/AMT-ACL.JPG" alt="AMT-ACL.JPG" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-11097-1374/AMT-ACL.JPG');return false;"/&gt;&lt;/li&gt;
&lt;li&gt;Click OK to save the changes.&lt;/li&gt;
&lt;/ol&gt;
&lt;p /&gt;
&lt;p /&gt;
To apply the updated or new profile to an AMT system Provisioning must occurred.  If the system was already provisioned with this same profile previously, a reprovision will update the profile.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;
This will not limit access to see the functions available in the Real-Time tab for AMT, but will throw a not authorized message if an applicable function is attempted with a user who does not have the rights to execute it.&lt;br /&gt;
&lt;p /&gt;
&lt;h1&gt;Conclusion&lt;/h1&gt;
&lt;br /&gt;
The Real-Time tab, a one-to-one solution for system access, data gathering, or troubleshooting, provides a powerful tool to IT administrators and IT professionals alike.  Providing this ability to users you do not want to have full access to Altiris is essential for any secure environment.  With the additional ability to configure granular AMT rights for vPro capable and configured systems, an administrator has the ability to get very specific on what users or groups of what rights.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">real-time_system_manager</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">intel</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">security</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <pubDate>Thu, 24 Apr 2008 16:39:44 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/04/24/how-to-configure-security-to-add-or-limit-access-to-the-realtime-tab-in-rtsm-for-intel-amt-technology-and-wmi-access</guid>
      <dc:date>2008-04-24T16:39:44Z</dc:date>
      <clearspace:dateToText>4 months, 1 week ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/how-to-configure-security-to-add-or-limit-access-to-the-realtime-tab-in-rtsm-for-intel-amt-technology-and-wmi-access</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=11097</wfw:commentRss>
    </item>
    <item>
      <title>Altiris and Intel vPro Use Cases - Introduction</title>
      <link>http://communities.intel.com/openport/blogs/proexpert/2008/01/11/altiris-and-intel-vpro-use-cases-introduction</link>
      <description>&lt;br /&gt;
The big question after successfully provisioning a vPro/Symantec-Altiris environment comes in the simple form of "Now what"?  The article series: Utilizing Intel&amp;reg; vPro AMT Technology with Task Server covers a lot of the functionality directly (LINK: &lt;a class="jive-link-external" href="http://juice.altiris.com/book-page/2201/utilizing-intel-vpro-amt-technology-with-task-server"&gt;http://juice.altiris.com/book-page/2201/utilizing-intel-vpro-amt-technology-with-task-server&lt;/a&gt;).  This article series takes it a few steps further, with real-world examples and use cases for taking advantage of Intel&amp;reg; vPro technology through Symantec/Altiris Notification Server.&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;Introduction&lt;/h1&gt;
&lt;br /&gt;
There are two components for directly interfacing the AMT vPro technology.  The first is Real-Time System Manager, the second Task Server.  Both components utilize much of the same functionality, however RTSM provides a one to one interface, while Task Server allows a one to many task or job to execute against a group of vPro systems.&lt;br /&gt;
&lt;p /&gt;
To understand how all the components work together, this Introduction walks through the basics of the components that will be used throughout the use cases.  The list of solutions, or applications, that utilize Intel vPro technology is listed here along with a description:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Real-Time Console Infrastructure - This component is generally invisible when working directly with vPro AMT Systems.  The Configuration of how to connect to systems and what credentials will be used can be found in the configuration pages for this product.  It supports both the Real-Time tab and the Task Server vPro AMT tasks available.&lt;/li&gt;
&lt;li&gt;Real-Time System Manager - The Real-Time tab functionality that directly interfaces with vPro AMT on a system per system basis provides a live tool for directly invoking vPro AMT functions as part of troubleshooting or maintaining a system directly.  This is useful for troubleshooting problems with a specific system.&lt;/li&gt;
&lt;li&gt;Out of Band Management - Out of Band Management will only lightly be covered in this article series.  For the most part this solution is part of the setup and configuration of Intel vPro AMT systems so that vPro AMT functionality can be used.  There are some maintenance and profile items that can be used as part of ongoing use of vPro AMT.&lt;/li&gt;
&lt;li&gt;Task Server - Task Server is the engine used for a one to many task or job where specific vPro AMT functions, along with functions from a myriad of other Solutions, can be executed or scheduled to execute against a collection or list of systems.  This is the integration framework that allows AMT to become part of a much larger Altiris functionality portfolio.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
See the following diagram for a representation of how the two main functional engines work:&lt;br /&gt;
&lt;p /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1203/RTSMvsTaskServer.jpg" alt="RTSMvsTaskServer.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1203/RTSMvsTaskServer.jpg');return false;"/&gt; &lt;br /&gt;
&lt;p /&gt;
This series will focus on these two pieces (RTSM and Task Server) since they are the delivery mechanism for the vPro AMT functionality.  Other Symantec Solutions can and will be used through the use cases.&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;Real-Time Console Infrastructure&lt;/h1&gt;
&lt;br /&gt;
Consider this the core underlining infrastructure for the Symantec use of Intel vPro AMT.  All solutions that make use of this component will install it if it is not already installed.  The primary products are Out of Band Management and Real-Time System Manager.  Other Notification Server Partner solutions, such as HPCM and Dell Openview, will need RTCI installed in order to make use of the vPro AMT functions.  The console pages available for this solution center around the configuration of the vPro AMT functions.&lt;br /&gt;
&lt;p /&gt;
The configuration page for RTCI is found in the Altiris Console.  In the Altiris Console 6.5, browse under View &amp;gt; Solutions &amp;gt; Real Time Console Infrastructure.  Under the Configuration folder, the following nodes are available:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Configuration - Includes settings for vPro AMT Connections, such as Transport Level Security, Redirection Security, and other settings such as the connection timeout value.  It also includes a page to configure where SNMP vPro AMT alerts are sent, and allows a default configuration for the System Defense filter (default is to &amp;lsquo;Allow all network traffic').&lt;/li&gt;
&lt;li&gt;Edit Network Filters - This page is only available if the ENF utility has been installed (see article &lt;a class="jive-link-external" href="http://juice.altiris.com/article/2645/hold-mf-utilizing-intel-vpro-amt-technology-task-server-part-5-system-defense-tasks"&gt;http://juice.altiris.com/article/2645/hold-mf-utilizing-intel-vpro-amt-technology-task-server-part-5-system-defense-tasks&lt;/a&gt; for more information).  If you do not have this node, install it so that you can configure what is allowed through the System Defense filter.&lt;/li&gt;
&lt;li&gt;Manage Credentials Profiles - This node is vital for setting up connection profiles when using RTSM.  It includes credentials for WMI and vPro AMT.  Users who do not have rights to vPro AMT will need to use a profile that has a user configured with rights.  This also includes the Run-Time profiles which is used by both Task Server and RTSM to use known good credentials when functioning against specific vPro AMT systems.&lt;/li&gt;
&lt;li&gt;Manage Views - Views are&lt;/li&gt;
&lt;li&gt;Purge Policy - This page is used to configure how often and how much residual data RTCI purges.  For large environments this will help keep the database size down to improve performance.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
The Reports, Resources, and Tasks section contain the typical items for Altiris Solutions.  Tasks include all the vPro tasks available through Task Server.  See the subsequent Task Server section for more details.&lt;br /&gt;
&lt;p /&gt;
The Tools folder is also found under the Real-Time System Manager section (it ties into the same data so the duplication is only visual).  For vPro AMT, the two applicable nodes are:&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Activity Log - This logs all functions executed while in a Real-Time session.  This is useful to look at what operations have been run, one which computers, by whom, and utilizing what technology (WMI versus vPro AMT).&lt;/li&gt;
&lt;li&gt;Manage - This node allows an IP address to be entered in directly for a launch of the Real-Time tab.  This is especially useful for systems that are not in the Altiris database.  This also allows a host-name to be entered, but keep in mind that if there is a DNS issue this may fail.&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1204/RTCIManage.jpg" alt="RTCIManage.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1204/RTCIManage.jpg');return false;"/&gt; &lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;Real-Time System Manager&lt;/h1&gt;
&lt;br /&gt;
To simplify things, we'll simply define this product as &amp;lsquo;The Real-Time tab within Resource Manager'.  There are Partner Solutions for HP, Dell, and others that will add items to the left-hand tree, but the Real-Time System Manager node provides all functionality including all vPro AMT functionality available.  See the following screenshot for details:&lt;br /&gt;
&lt;p /&gt;
&lt;img src="http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1205/RTSMvPro.jpg" alt="RTSMvPro.jpg" width="620" class="jive-image-thumbnail jive-image" onclick="myJiveImage.start(this, 'http://communities.intel.com/openport/servlet/JiveServlet/downloadImage/38-10838-1205/RTSMvPro.jpg');return false;"/&gt; &lt;br /&gt;
&lt;p /&gt;
NOTE: Only the vPro AMT functions are shown above as my Symantec Client Firewall is enabled!  Since vPro AMT is a trusted technology my Symantec firewall does not block vPro AMT traffic.&lt;br /&gt;
&lt;p /&gt;
The console is a direct connection to the machine listed under &amp;lsquo;Managing Resource'.  As such this is a one to one implementation and is useful when troubleshooting a specific vPro AMT system.  In the Use Cases where the use defines the target as one machine, often RTSM will be utilized.&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;Out of Band Management&lt;/h1&gt;
&lt;br /&gt;
Since Out of Band is primarily a Provisioning Solution, only a few of its functions will be used in the use-cases provided in this article series.  The functions that apply are:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Maintenance - For security purposes, OOBM can be setup to run maintenance tasks against managed vPro AMT systems.  The vPro AMT administrator password for a particular machine can be randomly changed.  A re-provision, which reassigns the profile assign to it, will help keep vPro AMT systems up to date with profile settings and password information.&lt;/li&gt;
&lt;li&gt;Profiles - In the profile setup while configuring an vPro AMT system users can be defined for having certain vPro AMT rights.  This allows administrators to limit what type of worker can execute what vPro AMT functions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;Task Server&lt;/h1&gt;
&lt;br /&gt;
Task Server is a sequencing engine, and RTCI provides vPro AMT targeted tasks that can be employed singly or jobs that can run a large variety of tasks or actions against a target collection of machines.  In the preface to this article a link provided access to a series focusing on how vPro tasks can be utilized into Task Server, with articles covering additional Altiris/Symantec Solutions for further integration.  Before walking through the Use Cases, it will help a great deal to understand how we're integrating the functionality and how Task Server functions in general.&lt;br /&gt;
&lt;p /&gt;
The vPro AMT tasks themselves are provided by RTCI, including the engine that connects and executes functions against a vPro capable system.  Task Server handles all the rest, including integrating other Solution functionality within Jobs.&lt;br /&gt;
&lt;p /&gt;
Most automated processes to be executed against one or more vPro AMT systems will fall under Task Server.  Task Server Jobs can be scheduled, or executed on demand.  Notification Server Collections or individually picked vPro AMT systems can be targeted per Task or Job, allowing a large number of systems to execute at a time (Note: for large environments multiple Task Servers are recommended).&lt;br /&gt;
&lt;br /&gt;
&lt;h1&gt;Conclusion&lt;/h1&gt;
&lt;br /&gt;
Before any of the Use Cases can be tested, all target AMT systems must be provisioned in one of the provisioning modes: Small Business (Low security), Enterprise Mode, Enterprise Mode with TLS.  Once provisioned, Symantec, via RTSM and Task Server, can then work directly with the machines via vPro AMT.&lt;br /&gt;
&lt;p /&gt;
I hope to cover common scenarios in this article series that can be of use to many environments.  Most of the testing will be against a limited lab environment so results may vary and additional configuration may be required, all depending on the complexity and configuration of the environment.  Since the hardware and software worlds introduce many levels of complexity and configuration, additional steps may be required to create workable jobs and functions.  Having said that, hopefully these provide enough information to move forward.</description>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">vpro</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">amt</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">altiris</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">symantec</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">notification_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">task_server</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">out_of_band_management</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtsm</category>
      <category domain="http://communities.intel.com/openport/blogs/proexpert/tags">rtci</category>
      <pubDate>Fri, 11 Jan 2008 22:44:26 GMT</pubDate>
      <author>joelsmith</author>
      <guid>http://communities.intel.com/openport/blogs/proexpert/2008/01/11/altiris-and-intel-vpro-use-cases-introduction</guid>
      <dc:date>2008-01-11T22:44:26Z</dc:date>
      <clearspace:dateToText>7 months, 3 weeks ago</clearspace:dateToText>
      <wfw:comment>http://communities.intel.com/openport/blogs/proexpert/comment/altiris-and-intel-vpro-use-cases-introduction</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/openport/blogs/proexpert/feeds/comments?blogPostID=10838</wfw:commentRss>
    </item>
  </channel>
</rss>

