- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Link Copied
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello TheDrowsyWhaler,
Based on our review, Intel vPro Fleet Services does not support provisioning Entra-only devices into ACM without supplying a DNS/domain suffix.
For ACM (Unattended Access) provisioning, an Intel AMT provisioning certificate associated with your domain is required. The certificate must contain the DNS suffix in its Common Name (CN) and be uploaded to the Intel vPro Fleet Services console. The endpoint validates this certificate using trusted CA hashes that are preinstalled in the Intel AMT firmware.
If your devices are not connected to your on-premises domain and therefore do not receive the DNS suffix through DHCP Option 15, the supported approach is to use Minimal Touch provisioning, where the DNS suffix is manually configured on the endpoint using USB pre-provisioning or MEBx.
Additionally, it is not necessary to have a dedicated server to generate the private key required for the certificate request. You can generate the private key (CSR) from a single endpoint by installing IIS on that endpoint. Once the certificate is issued, it should be uploaded to the Intel vPro Fleet Services console for ACM provisioning.
How to Purchase and Install a public GoDaddy*, DigiCert*, or Sectigo* Certificate for Intel® vPro Fleet Services
https://www.intel.com/content/www/us/en/support/articles/000103058/technologies.html
VijayN_Intel
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page