|
Key Capabilities of Intel® AMT in the Enterprise Environment
Intel AMT provides three key capabilities for the enterprise's IT managers to simplify their
daily workload and significantly reduce IT operating costs.
Remotely Discover Computing Assets in Any State
Accurate platform, software, and hardware inventories are necessary for regulatory compliance
as well as for accurately managing maintenance contracts and software licenses. There are some
in-band tools available today for remote inventory, but they miss platforms that are powered
down, have been tampered with, or have an OS problem. As a result, IT enterprise departments
often have to maintain lengthy and expensive manual inventory to ensure accuracy. By contrast,
Intel AMT eliminates manual inventory costs by using OOB management tools and tamper-resistant
agents in NVM to discover all network-connected computing assets.

Figure 1: Remotely discovering
click image for larger view
Figure 1 illustrates the Intel AMT discover process. Here a third-party or Independent Software
Vendor's (ISV) management application polls network-connected PCs to discover inventory.
Because polling occurs through OOB communication, even powered-down and OS-disabled platforms
are discovered. Additionally, because of the tamper-resistant agents and NVM features, a full
and accurate inventory of the platform's hardware and software is always available through
Intel AMT.
Remotely Diagnose and Heal Computing Assets
In the past, an inoperable OS, corrupted application, or crashed hard drive invariably required
at least one or two desk-side visits to fix the problem. The proactive alerting and remote-boot
capabilities of Intel AMT can reduce the number of desk-side visits and even eliminate them in
some cases by remotely healing the platform problem. Figure 2 illustrates the process of
remotely healing computing assets.

Figure 2: Remotely diagnosing and healing
click image for larger view
In the first step shown in Figure 2, a problem occurs in one of the platforms and the Intel AMT
proactive alerting feature notifies the IT management console. Depending on the type of problem
alert, IT can remotely reboot the platform to an IT diagnostics platform if necessary (step 2
in Figure 2). Remote reboot would be necessary, for example, when the platform's OS becomes
unstable or locks up, or if there is a hard-drive failure. Even with the OS down or a drive
failure, Intel AMT's proactive alerts and remote reboot still function because they occur using
OOB communication. Once IT has control of the platform using remote reboot, third-party
diagnostics can be used to diagnose the problem and define a repair solution to heal the system
(step 3, 4 in Figure 2).
Remotely healing assets using Intel AMT provides faster time-to-repair and significantly
reduces desk-side visits, thus increasing IT efficiency and reducing maintenance costs.
Remotely Protect Computing Assets
For an enterprise, it is important to protect computing assets and maintain corporate
productivity by ensuring that each platform has the latest IT-approved software versions
installed. This minimizes file and operating incompatibilities that can occur when different
departments or groups use differing application software versions. In particular, it is vital
to protect against virus attacks by ensuring that anti-virus software and virus-definition
files are kept up to date on all platforms.
While in-band tools are available for identifying and updating anti-virus software, their OS-level
agents can be accidentally removed or overwritten. Additionally, in-band tools cannot
work if the platform is powered down or its OS is not available.
The OOB capability of Intel AMT allows remote maintenance of anti-virus software, regardless of
platform state. This is shown in Figure 3, where an ISV application operating through Intel AMT
checks platform software version numbers. Upon finding an out-of-date version number, IT can
wake the platform for off-hours version updates or patches.

Figure 3: Remotely protecting
click image for larger view
Complete software update and patching is done remotely through Intel AMT, eliminating desk-side
visits and ensuring that enterprise protection is current across all Intel AMT-enabled
platforms.
Home PC Maintenance Through Intel AMT
The most common issues with home PCs are virus infection, software installation or
configuration problems, and hardware problems. These issues often result in OS errors or even
OS crashes. Once these problems occur, home PC users, with little knowledge about computer
technology, are forced to call support centers and spend time on the phone, or sometimes they
even have to request a site visit from a technician. The remote-diagnose and remote-heal
capabilities of Intel AMT can eliminate these kinds of costly and frustrating tasks. The
process used for remotely healing in the enterprise environment (Figure 2) also can be used to
remotely heal a home PC with Intel AMT.
When a problem occurs in a home PC that is enabled with Intel AMT, the user can inform the IT
technician about the problem. The IT technician remotely connects to the home PC and reboots
the system to control the remote machine. The serial and Integrated Device Electronics (IDE)
communications are redirected from the home PC client to the management console. The only
requirement is that the home PC be connected to the network and have standby power.
Once the IT technician has control of the platform, third-party diagnostic tools can be used to
diagnose the problem. If it is a virus infection, the IT technician can eliminate it with anti-virus
software. If the virus cannot be deleted, the IT technician can re-install the OS. During
this period of time, users need not be at home: all of these operations can be done by the IT
technician remotely without the intervention of the user.
If the failure is diagnosed as a hardware problem, such as a problem with a hard disk drive,
Intel AMT can access the platforms' NVM, in which inventory information is stored, to determine
the disk drive make, model, and warranty status. The technician can then check if this disk
drive is available at a certain location and convey this information to the user;
alternatively, the technician can arrange for this hard drive to be sent to the user's home or
place of business.
Remotely healing home PCs using Intel AMT is significantly easier for users. Furthermore, AMT
can provide faster time-to-repair with home PC users and decrease the cost of maintenance. Due
to the difference in the network environment of an enterprise versus a home PC, a special usage
model is needed in order for Intel AMT to remotely fix a home PC. We now discuss this usage
model.
|