The problem likely is something related to certificates.
Are you able to perform collection based power control commands against the client? You can test this by right clicking on a client, choosing the out-of-band management menu and then power control. Try turning the system on or off. If this works, that means that AMT has a good certificate. If it doesn’t work, try accessing the WebUI on the system using it's FQDN and see if your browser gives you any certificate errors.
If the test above is successful, the problem is likely with the way your CA chain is trusted. You may need to put the certs for all of your CA's into the trusted root store on the system you are running the SCCM console app on. This would include any intermediary CA's (like policy CA's) as well as the actual issuing CA.