Article ID: 000056823 Content Type: Install & Setup Last Reviewed: 09/01/2022

Can I Use Intel® Endpoint Management Assistant to Provision Intel® AMT When a System Is Not on the Corporate Network, without Manually Performing a Intel® MEBx Operation on Each Endpoint?


Version: Intel® EMA


Steps and limitations for activating Intel® Active Management Technology (Intel® AMT) with Intel® EMA inside and outside of corporate network


In the Intel® EMA platform video series, the presenter alludes in one slide to TLS Provisioning vs CIRA Provisioning.


Unfortunately, the answer is no. For clarification, Intel® Endpoint Management Assistant (Intel® EMA) can be used to provision (activate) Intel® AMT outside of the corporate network.

If you are using an Intel AMT provisioning certificate to activate Intel® AMT on your devices, the situation is similar to Intel® Setup and Configuration Software (Intel® SCS) regarding Dynamic Host Configuration Protocol (DHCP) option 15 or setting PKI DNS suffix in the Intel® Management Engine BIOS Extension (Intel® MEBX).

Intel® AMT on the device can be activated by Intel® EMA if it is on the corporation network with DHCP option 15 matching the DNS suffix in the provisioning certificate installed on EMA server, or outside the corporate network but having the PKI DNS suffix manually entered in Intel MEBx matching the certificate.