ThinkCentreM92/pandM92z
IntelActiveManagementTechnology
CongurationGuide
ThinkCentreM92/pandM92z
IntelActiveManagementTechnology
CongurationGuide
Note:Beforeusingthisinformationandtheproductitsupports,readthegeneralinformationinAppendixC
“Notices”onpage25.
FirstEdition(May2012)
©CopyrightLenovo2012.
LIMITEDANDRESTRICTEDRIGHTSNOTICE:IfdataorsoftwareisdeliveredpursuantaGeneralServicesAdministration
“GSA”contract,use,reproduction,ordisclosureissubjecttorestrictionssetforthinContractNo.GS-35F-05925.
Contents
Aboutthisdocument..........v
Chapter1.IntroductiontoIntelvPro
andIntelAMT..............1
Acronyms.................1
Clientsystemrequirements...........2
Chapter2.Featuresandbenetsof
IntelAMT................3
Featuresandbenets.............3
Chapter3.Mainfeaturesof
computersbuiltwithIntelAMT.....5
CIRA...................5
KVMredirection...............6
HostBasedProvisioning............6
Chapter4.IntelAMTsetupand
congurationonLenovoThinkCentre
M92/pandM92zdesktopcomputers..7
IntelAMTcongurationsettingsinSetupUtility...7
IntelMEBxsetupandconguration.......8
EnteringtheMEBxcongurationuser
interface................8
Intel(R)MEGeneralSettings........8
Intel(R)AMTConguration........11
Driverdescription.............18
MEI.................18
LMS.................18
SOL.................18
Chapter5.Webuserinterface....19
AccessingtheWebuserinterface.......19
ConguringtheIntelAMTcomputer....19
Loggingontotheclient.........20
FunctionsintheWebuserinterface......20
AppendixA.Examplesofconguring
IntelAMTinmanualandautomatic
setupandcongurationmodes...21
ConguringIntelAMTinmanualsetupand
congurationmode.............21
ConguringIntelAMTinautomaticsetupand
congurationmode.............21
ZTCprovisioning............21
USBprovisioning............22
AppendixB.Factorydefaultsettings
fortheIntelMEBx...........23
AppendixC.Notices..........25
Trademarks................26
©CopyrightLenovo2012
iii
ivThinkCentreM92/pandM92zIntelActiveManagementTechnologyCongurationGuide
Aboutthisdocument
ThisdocumentprovidesinformationaboutIntel
®
ActiveManagementT echnology(IntelAMT)forLenovo
ThinkCentre®M92/pandM92zdesktopcomputers.Thisdocumentprovidesstep-by-stepinstructionson
howtouseIntelAMT.
ThisdocumentisintendedfortrainedITprofessionalsorthoseresponsibleforconguringcomputers
throughouttheirorganizations.Thereadersshouldhavebasicknowledgeofnetworkandcomputer
technology,andbefamiliarwiththetermsTCP/IP,DHCP ,IDE,DNS,SubnetMask,DefaultGateway,Domain
Name,andsoon.
Thisdocumentprovidesinformationaboutthefollowingtopics:
Chapter1“IntroductiontoIntelvProandIntelAMT”onpage1:Thischapterprovidesageneralintroduction
toIntelvPro
™
andIntelAMT.
Chapter2“FeaturesandbenetsofIntelAMT”onpage3:Thischapterintroducesthefeaturesand
benetsofIntelAMT.
Chapter3“MainfeaturesofcomputersbuiltwithIntelAMT”onpage5:Thischapterintroducesthemain
featuresofIntelAMTbuilt-incomputers.
Chapter4“IntelAMTsetupandcongurationonLenovoThinkCentreM92/pandM92zdesktopcomputers”
onpage7:ThischapterprovidesdetailedinstructionsonhowtocongureIntelAMTsettingsonLenovo
ThinkCentreM92/pandM92zdesktopcomputers.
Chapter5“Webuserinterface”onpage19:Thischapterprovidesinstructionsonhowtoaccessthe
IntelAMTWebuserinterface.
®
©CopyrightLenovo2012
v
viThinkCentreM92/pandM92zIntelActiveManagementTechnologyCongurationGuide
Chapter1.IntroductiontoIntelvProandIntelAMT
IntelvProisabusinesscomputerplatformthatprovidesbusinesscomputerswithenhancedremote
managementcapabilities.ForcomputersbuiltwithIntelvPro,ITadministratorscanuseathirdpartysoftware
toremotelycollectinventoryinformation,diagnoseproblems,andprovidevariousservicesregardlessof
thecomputerpowerstateortheoperatingsystemstate.ITadministratorscanalsoisolateandprotect
individualcomputersandthenetworkfromthreats.
AsafeatureofIntelvPro,IntelAMTisdesignedtoprovideremotemanagementofcomputersregardless
ofthecomputerpowerstateortheoperatingsystemstateaslongasthecomputersareconnectedtoan
electricaloutletandanetwork.
IntelAMTisdesignedasabuildingblockandnotacompletesolution.ThisenablesOriginalEquipment
Manufacturers(OEMs)toincorporateIntelAMTintotheirclientandserverhardwareplatforms.Competent
andauthorizedthirdpartyapplicationsprovidemanagementandsecurityservicesthattakeadvantageof
theIntelAMTfeatures,suchasout-of-bandaccesstoassetinformation,eventlogs,hardwareandsoftware
tables,andembeddedcapabilities.
Acronyms
Thefollowingtablelistsandexplainssomeacronymsusedinthisdocument.
AcronymDescription
ACLAccessControlList
AMTActiveManagementTechnology
ASFAlertStandardFormat
BIOSBasicInputOutputSystem
CIRAClientInitiatedRemoteAccess
DHCPDynamicHostCongurationProtocol
DNSDomainNameServer
FQDNFullyQualiedDomainName
FWFirmware
HBPHostBasedProvisioning
HECIHostEmbeddedControllerInterface
IDE-RIntegratedDeviceElectronics-Redirection
IPInternetProtocol
ISVIndependentSoftwareVendor
KVMKeyboard-Video-Mouse
LMSLocalManageabilityService
MEManagementEngine
MEBx
MEI
NVMNonvolatilememory
OEMOriginalEquipmentManufacturer
ManagementEngineBIOSExtension
ManagementEngineInterface
©CopyrightLenovo2012
1
AcronymDescription
OOBOut-of-band
PID/PPS
PKI
PRTCProtectedRealTimeClock
PSK
PXEPrebootExecutionEnvironment
RCFGRemoteConguration
SHASecureHashAlgorithm
SMBSmallandMediumBusinesses
SOLSerial-over-LAN
SPISerialPeripheralInterface
TCPTransmissionControlProtocol
TLSTransportLayerSecurity
WOL
ZTCZeroTouchConguration
ProvisioningIDandProvisioningPre-sharedKey
PublicKeyInfrastructure
Pre-sharedKey
WakeonLAN
Clientsystemrequirements
ThefollowingrmwareandsoftwarerequirementsmustbemetbeforetheIntelManagementEnginecanbe
conguredandrunontheclientsystem:
•TheSPIashdeviceprogrammedwiththeIntelAMT8.0ashimageintegratingBIOS,IntelManagement
Engine,andGbEcomponentimagesisinstalled.
•TheBIOSissetupwithIntelAMTenabled.
•Devicedrivers(IntelMEI/SOL/LMS)areinstalledandconguredontheclientsystemtoensurethatallof
theIntelManagementEnginefeaturesworkcorrectly.
2ThinkCentreM92/pandM92zIntelActiveManagementTechnologyCongurationGuide
Chapter2.FeaturesandbenetsofIntelAMT
ThischapterintroducesthefeaturesandbenetsofIntelAMT.
ThefollowingtableliststheLenovobusinesscomputerswithIntelAMTinstalled.
LenovocomputerIntelAMTversion
ThinkCentreM92z
ThinkCentreM92/p
ThinkCentreM91p
ThinkCentreM90p
ThinkCentreM58p
ThinkCentreM57p
ThinkCentreM55p
Featuresandbenets
ThinkCentreM92/pandM92zcomputersbuiltwithIntelAMTenableITadministratorstobetterdiscover,
heal,andprotectthenetworkedcomputingassets.
•Discover:IntelAMTstoreshardwareandsoftwareinformationinnonvolatilememory(NVM).Withbuilt-in
manageability,IntelAMTenablesITadministratorstodiscoverassetsremotely,evenwhencomputersare
turnedoff.
•Heal:Thebuilt-inmanageabilityofIntelAMTprovidesout-of-band(OOB)managementcapabilities,which
enableITadministratorstoremotelydiagnosecomputerproblemsandrecovercomputersevenifthe
operatingsystemsareinoperable.ProactivealertingandeventlogginghelpITadministratorsdetect
problemsquicklytoreducecomputerdowntime.
•Protect:TheIntelAMTsystemdefensefeatureenablesbetterprotectionforcomputersbyproactively
blockingincomingthreats,controllinginfectedcomputersbeforethecomputerscauseproblemsinthe
network,andalertingITadministratorswhencriticalsoftwareagentsareremovedfromthecomputers.
IntelAMT8.X
IntelAMT8.X
IntelAMT7.X
IntelAMT6.X
IntelAMT5.X
IntelAMT3.X
IntelAMT2.X
ThefollowingtableshowsthefeaturesandbenetsofIntelAMT.
Table1.FeaturesandbenetsofIntelAMT
FeaturesBenets
OOBsystemaccess
Remotetroubleshootingandrecovery
ProactivealertingDecreasescomputerdowntimeandminimizesITservice
RemotehardwareassettrackingIncreasesspeedandaccuracywithreducedaccounting
©CopyrightLenovo2012
Enablesremotemanagementofclientsregardlessof
clientpowerstateandoperatingsystemstate
SignicantlyreducesIThelpdeskvisitsandincreasesIT
serviceefciency
time
costs,comparedwithmanualinventorytracking
3