Intel vPro® Platform
Intel Manageability Forum for Intel® vPro Fleet Services, EMA, AMT, SCS & Manageability Commander.
Announcements
Important Update: Community Platform Migration​. Learn more​>
3091 Discussions

ACM without Domain Suffix

TheDrowsyWhaler
Beginner
537 Views
Can Intel vPro Fleet Services provision Entra-only devices into ACM without supplying our Domain suffix? I have a hybrid environment and our Entra only devices do not connect to our domain. 
0 Kudos
1 Reply
VijayN_Intel
Employee
461 Views

Hello TheDrowsyWhaler,

 

Based on our review, Intel vPro Fleet Services does not support provisioning Entra-only devices into ACM without supplying a DNS/domain suffix.

 

For ACM (Unattended Access) provisioning, an Intel AMT provisioning certificate associated with your domain is required. The certificate must contain the DNS suffix in its Common Name (CN) and be uploaded to the Intel vPro Fleet Services console. The endpoint validates this certificate using trusted CA hashes that are preinstalled in the Intel AMT firmware.

 

If your devices are not connected to your on-premises domain and therefore do not receive the DNS suffix through DHCP Option 15, the supported approach is to use Minimal Touch provisioning, where the DNS suffix is manually configured on the endpoint using USB pre-provisioning or MEBx.

 

Additionally, it is not necessary to have a dedicated server to generate the private key required for the certificate request. You can generate the private key (CSR) from a single endpoint by installing IIS on that endpoint. Once the certificate is issued, it should be uploaded to the Intel vPro Fleet Services console for ACM provisioning.

 

How to Purchase and Install a public GoDaddy*, DigiCert*, or Sectigo* Certificate for Intel® vPro Fleet Services

https://www.intel.com/content/www/us/en/support/articles/000103058/technologies.html

 

VijayN_Intel

0 Kudos
Reply