Currently Being Moderated
This is an archived version of the document. The current version can be viewed here.

Intel® vPro™ Technology SMB & MSP Provisioning Method Selection Guide

 

Intel vPro Technology delivers many high-performance features and innovative capabilities for both users and IT administrators - all in an energy-efficient platform that is Microsoft Windows Vista* ready.  Among the innovative capabilities of the Intel vPro technology are Intel Active Management Technology (Intel AMT).

 

Intel AMT is a powerful hardware-based technology for security and remote management of computers.  With Intel AMT, managed service providers (MSPs) can monitor and manage computers anytime - even if a wired computer's power is off, the OS on a wired or wireless computer is inoperable, management agents are missing, or hardware (such as a hard drive) has failed.  When integrated into a third-party management solution, computers with Intel vPro Technology let service providers spend less time managing the computer and more time focusing on strategic business initiatives.

 

 

 

 

Intel AMT must be configured with the appropriate security, network, and operational parameters before a third-party management application can access the Intel AMT capabilities.  If you do not configure Intel AMT before trying to integrate into the management application, the integration process will fail.


To turn on the value of Intel vPro Technology, there are three options for configuring Intel AMT:

 

  1. Manual Configuration of Intel® vPro™ Technology Systems (Basic Mode) (for a few computers): Entering the BIOS and Management Engine BIOS Extension (MEBx) to configure Intel AMT.  Several documents are available at this link to step through the required setup screens in the BIOS and MEBx.
     
  2. Improved Manual Configuration of Intel® vPro™ Technology Systems (Basic Mode) (using software utility & USB key): Intel AMT Activator is a Microsoft Windows* utility included in the Intel Setup and Configuration Service (SCS) 6.0 Lightweight download available at the link below.  This utility helps create a USB key to locally configure Intel AMT (available only for Intel AMT version 4.0 and above).  The Intel AMT Activator utility must be run on each machine; but does not require installing the SCS 6.0 Lightweight service in the network, or manually accessing the BIOS screens.
  3. Automatic Configuration (using SCS 6.0 Lightweight service): Intel SCS 6.0 Lightweight is a provisioning service, designed for small businesses and their service providers, that will automate Intel AMT configuration.  The lightweight version requires minimal infrastructure to accommodate smaller sites.  It requires installing a service on one server or computer in a network.  The service keeps a profile which is used to configure Intel AMT settings for all the computers in the network.  With the service installed, there are two methods for configuring systems:

    1. Pre-Shared Keys (PSK): Keys are created by the SCS service and loaded onto each client computer.  The pre-shared key establishes a trust between the SCS service and the client computer.  Once trust is established, an activator utility is run on the client computer to request AMT configuration (via the profile).

    2. Certificates (PKI): A special certificate can be purchased and installed on the computer hosting the SCS service.  With this certificate installed, the AMT client computers can automatically trust the service and the activator utility can be run on each client to configure AMT (via the profile). The network must have a DHCP server capable of configuring option 15 in order for certificates to work properly.

 

 

ManualImproved ManualAutomatic (PSK)Automatic (PKI)
Level of Effort

Labor Intensive

  • Must visit every PC for initial & on-going configuration
  • Must access the BIOS to make changes
  • Error Prone
  • English Ony

Less Labor Intensive

  • Must visit every PC for initial & on-going configuration
  • Less Error Prone
  • Localized

Less Labor Intensive

  • Must visit every PC for initial config, not on-going
  • Least error prone
  • Localized

Least Labor Intensive

  • Never requires a visit to the PC
  • Least Error Prone
  • Localized
Preparation
  • None
  • USB key purchase
  • Download Intel SCS Activator Utility
  • USB key purchase
  • Download & install
    Intel SCS
  • Security Certificate Purchase
  • DHCP server with option 15
  • Download & install Intel SCS

Comments

Delete Document

Are you sure you want to delete this document?

More Like This

  • Retrieving data ...