Intel AMT woes

(imported topic written by MattBoyd)

I’m curious, how many of the BigFix admins out there are using Intel’s Active Management Technology? Has it caused any issues in your environment?

Many of our systems came with this feature enabled, but not configured. Unfortunately, it seems to be the cause of some issues that we’re having with power management and logons.

On a particular system model, we updated the BIOS, which apparently updated the Intel ME/AMT firmware as well. Since doing that, the machines no longer respond to keyboard, mouse, or wake-on-lan if they’ve been asleep for longer than 15 minutes. On two other models, users are receiving temporary profiles, or unable to log in after login because the Intel network adapter disconnects and reconnected multiple times. In both of these cases, disabling AMT solved our problems.

Since we don’t use AMT (and, quite frankly, don’t find it to be much more than a backdoor on the system), we’d like to disable it. However, all of my research indicates that Intel failed to provide a way to do this remotely! Therefore, we’re considering physically visiting nearly 1800 machines this week and disabling it. Good grief.

Does anyone know of a way to disable it remotely (preferably, through BigFix)? It appears that some system manufacturers include a way to disable it via the BIOS, but ours doesn’t. We can only disable it through the MEBx at this point.