Intel AMT built-in computers. Chapter 4 “Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers” on page 7: This chapter provides detailed instructions on how to configure Intel AMT settings on Lenovo ThinkCentre M92/p and M92z desktop computers.
Page 8
ThinkCentre M92/p and M92z Intel Active Management TechnologyConfiguration Guide...
Acronym Description Out-of-band PID/PPS Provisioning ID and Provisioning Pre-shared Key Public Key Infrastructure PRTC Protected Real Time Clock Pre-shared Key Preboot Execution Environment RCFG Remote Configuration Secure Hash Algorithm Small and Medium Businesses Serial-over-LAN Serial Peripheral Interface Transmission Control Protocol Transport Layer Security Wake on LAN Zero Touch Configuration...
Chapter 2. Features and benefits of Intel AMT This chapter introduces the features and benefits of Intel AMT. The following table lists the Lenovo business computers with Intel AMT installed. Lenovo computer Intel AMT version Intel AMT 8.X ThinkCentre M92z ThinkCentre M92/p Intel AMT 8.X...
Page 12
ThinkCentre M92/p and M92z Intel Active Management TechnologyConfiguration Guide...
• Scheduled, automated call-home feature (no user input required) • Transport Layer Security (TLS) session established through client initiation KVM redirection ThinkCentre M92/p and M92z computers built with Intel AMT 8.X support Keyboard-Video-Mouse (KVM) redirection over Internet Protocol (IP). KVM redirection enables IT administrators to remotely control the keyboard, video or visual display unit, and mouse of the managed clients.
Chapter 4. Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers The Intel Management Engine (ME) is an isolated and protected computing resource that runs on an Intel AMT computer. The Intel Management Engine BIOS Extension (MEBx) provides a user interface to change or configure settings that control the operation of the Intel Management Engine (ME).
Option Default setting Description Enabled Intel(R) Manageability Control Used to enable or disable the Intel(R) Manageability interface. Disabled Used to enable or disable the Intel Intel(R) Manageability Reset AMT reset function. Press <Ctrl-P> to Enter MEBx Enabled Used to enable or disable the entrance of the MEBx setup configuration menu.
Page 17
MEBx again, you will find that the password has been successfully reset to “admin”. FW Update Settings Select FW Update Settings and press Enter. The FW Update Settings window opens. Chapter 4 Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers...
Option Description Local FW Update You can enable, disable, or use the MEBx password to protect the Intel ME firmware local update. When the Local FW Update option is set to ENABLED, the IT administrator can update the Intel ME firmware locally through the local Intel ME interface or through the local secure interface.
“Remote Setup And Configuration” on page 15 Manageability Feature Selection The Manageability Feature Selection option is used to enable or disable the Intel ME manageability feature. The default setting is ENABLED. Chapter 4 Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers...
Note: If you disable the Manageability Feature Selection function, all the network settings including ACLs will be reset to factory default settings. SOL/IDER/KVM Select SOL/IDER/KVM in the INTEL(R) AMT CONFIGURATION window and press Enter. The SOL/IDER/KVM window opens. The following options will be displayed. Description Option Username &...
Intel(R) ME Network Name Settings In the INTEL(R) ME NETWORK SETUP window, select Intel(R) ME Network Name Settings and press Enter. The following options will be displayed. Chapter 4 Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers...
Option Description Host Name Enables you to set a host name for your Intel AMT computer. Domain Name Enables you to set a domain name for your Intel AMT computer. Shared/Dedicated FQDN Dedicated – The FQDN domain name is dedicated to Intel ME.
“Provisioning Server IPV4/IPV6” on page 16 • “Provisioning Server FQDN” on page 16 • “RCFG” on page 16 • “TLS PSK” on page 16 • “TLS PKI” on page 17 Chapter 4 Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers...
Page 24
Current Provisioning Mode The Current Provisioning Mode option shows you the current provisioning TLS mode: None, PKI (Public Key Infrastructure), or PSK (Pre-shared Key). Provisioning Record The Provisioning Record option shows you the provision PSK or PKI record data of your computer. If no data has been entered, a message will be displayed indicating that the provision record is not present.
Page 25
SHA-2. Enter the hash data in the correct format and then press Enter. Note: You can choose which hash algorithm will be used. a. SHA1 b. SHA2-256 c. SHA2-384 Chapter 4 Intel AMT setup and configuration on Lenovo ThinkCentre M92/p and M92z desktop computers...
Option Description 3. Press Y to activate the certificate hash when prompted. • Delete: Used to delete the currently selected certificate hash. A certificate hash that is not active cannot be deleted. • +: Used to change the active state of the currently selected certificate hash.
Note: You can refer to detailed configuration examples for both manual setup and configuration mode and automatic setup and configuration mode in Appendix A “Examples of configuring Intel AMT in manual and automatic setup and configuration modes” on page 23 Logging on to the client The client can be accessed from a management console on the network that has a supported Web browser.
Chapter 6. PC Cloud Manager PC Cloud Manager (PCM) is a free program that enables Lenovo customers to use AMT functions supported by the Intel vPro technology, such as power control, KVM, and IDER, on Lenovo ThinkCentre computers. To download the program and the installation instructions, go to: http://support.lenovo.com/en_US/downloads/detail.page?DocID=DS029429...
Page 30
ThinkCentre M92/p and M92z Intel Active Management TechnologyConfiguration Guide...
6. In the INTEL(R) ME NETWORK SETUP window, select TCP/IP Settings and press Enter. Configure TCP/IP settings in the TCP/IP SETTINGS window. 7. In the INTEL(R) AMT CONFIGURATION window, select Remote Setup And Configuration ➙ TLS PKI ➙ Manage Hashes. Press Insert and then set up your own certificate hashes. 8.
Page 34
Table 2. Factory default settings for the Intel MEBx (continued) Default setting Default setting Option Option Entrust Root CA VeriSign Universal Root CA Lenovo AMT Host Name Domain Name Shared/Dedicated FQDN Shared ThinkCentre M92/p and M92z Intel Active Management TechnologyConfiguration Guide...
Lenovo representative for information on the products and services currently available in your area. Any reference to a Lenovo product, program, or service is not intended to state or imply that only that Lenovo product, program, or service may be used. Any functionally equivalent product, program, or service that does not infringe any Lenovo intellectual property right may be used instead.
Trademarks Lenovo, the Lenovo logo, and ThinkCentre are trademarks of Lenovo in the United States, other countries, or both. Microsoft and Windows are trademarks of the Microsoft group of companies. Intel and Intel vPro are trademarks of Intel Corporation in the United States, other countries, or both.