Appearance
Intel AMT Endpoint Management
The Intel AMT endpoint tab shows firmware capability, configuration, provisioning, security, and out-of-band operations for a Windows endpoint. Basic AMT hardware inventory remains available to users who can read the endpoint. Management data and actions require an AMT role.
AMT can remain reachable when the operating system or Ordyn agent is offline after provisioning. Firmware must still have power and network connectivity, and the assigned AMT client must be connected.
Firmware compatibility
Intel AMT support is best effort. Ordyn has been tested with AMT 11.x and 16.x firmware only. Other firmware versions have not been validated and may behave differently. Validate the required provisioning, recovery, power, KVM, SOL, and media-redirection workflows on representative devices before production use.
Understand the Device State
AMT state is shown as separate fields. Do not infer one field from another.
| Field | Values | Meaning |
|---|---|---|
| Hardware support | supported, unsupported, unknown | Whether authoritative firmware evidence confirms AMT capability |
| Firmware enablement | enabled, disabled, unknown | Whether AMT is enabled in firmware |
| Provisioning | unprovisioned, provisioning, provisioned, unknown | Configuration progress |
| Control mode | none, ccm, acm, unknown | Current firmware management mode |
| Ownership | unmanaged, external, managed, recovery_required | Whether Ordyn controls the configuration |
| Configuration | unassigned, disabled, pending, compliant, drifted, blocked | Effective Intel AMT configuration result |
| Reachability | unknown, reachable, unreachable, client_offline | Current AMT-client path state |
A disabled AMT firmware state can still be supported. A successful diagnostic means that the diagnostic ran; its evidence may still be negative or inconclusive. Intel ME or CSME firmware by itself does not prove AMT support. Missing SMBIOS Type 131, unavailable Intel WMI, or unavailable providers produce unknown. Unsupported requires an authoritative negative MEI/PTHI result with no stronger positive evidence.
AMT Availability
Ordyn checks each managed AMT device about every five minutes by making an authenticated, read-only power-state request through its assigned AMT client. The check uses the stored Intel AMT interface address, the expected AMT name and certificate authority, and the managed administrator credential. It does not depend on the Windows agent and does not create an endpoint history entry.
A violet dot before the normal connection indicator in the endpoint sidebar means that this authenticated check succeeded recently. It is shown independently of the agent connection, including while the agent is connected. The dot expires automatically when the successful observation becomes stale and disappears immediately after a failed check. Only users who can read Intel AMT management data see this indicator.
Unreachable means that the AMT client could not establish or complete the network request. Unknown means that Ordyn could not verify availability, for example after a TLS, identity, protocol, or authentication failure. Client offline means that the assigned AMT client is disconnected. Failed devices are retried with increasing delays up to 15 minutes. Reconnecting the AMT client, changing the AMT address, disconnecting the Windows agent, or completing provisioning schedules a new check promptly.
Open the evidence and diagnostics section to compare SMBIOS, WMI, MEI/PTHI, LMS, firmware, and capability results. Error entries retain useful Windows error categories and codes without exposing secrets.
Device Requirements
Agent-assisted provisioning supports:
- Intel AMT 11 or newer
- a supported 64-bit Windows installation
- the Ordyn agent running as its normal LocalSystem service
- a working OEM Intel Management Engine Interface (MEI) driver
- a running Intel Local Manageability Service (LMS)
- an online agent connected through its assigned Edge during preflight and provisioning
Ordyn reports the exact detected MEI and LMS versions and provides an OEM remediation message when either prerequisite is missing. It does not install or update OEM MEI, LMS, BIOS, or ME firmware.
Linux inventory may report AMT firmware evidence. Linux provisioning and Linux MEI/PTHI management are unsupported.
AMT 11–13 Provisioning
Ordyn supports CCM and ACM provisioning on AMT 11–13 through the Windows agent and the device's local Intel LMS connection. The compatibility connection is restricted to localhost during an authorized provisioning or recovery operation. Ordyn installs an RSA-2048 operational firmware certificate, enables TLS, and verifies the managed name and exact certificate before the AMT client continues directly on port 16993.
Putting an AMT 11–13 device into ACM, including a CCM-to-ACM transition, requires:
- an Ordyn RSA-2048/SHA-256 activation credential whose root is trusted by firmware
- the same DNS suffix in firmware, the activation credential, and the effective Intel AMT configuration profile
- an enabled wired interface with link and DHCP
- a valid planned shared-DHCP address from the endpoint's wired interface
If no active, valid, unexpired RSA credential meets these trust and DNS requirements, provisioning stops without changing the firmware. Ordyn does not create a credential automatically or switch the endpoint to CCM. Create the credential, apply a setup.bin generated from it, and run preflight again before retrying.
These activation requirements do not apply to same-mode adoption of a supported device that is already provisioned in CCM or ACM. That workflow uses the device's current Intel AMT administrator password, preserves its ACM provisioning-trust hashes, replaces the WS-Man certificate store, and installs an Ordyn operational TLS certificate without running control-mode activation.
Unprovisioned AMT 11–13 firmware may report its address as 0.0.0.0 before activation. Ordyn uses the planned shared-DHCP address during setup and verifies the firmware address after activation.
The device does not need a Wi-Fi adapter. Wi-Fi is optional on every supported AMT version; Ordyn provisions the wired AMT interface and does not configure firmware Wi-Fi settings.
Configuration Profiles
Create an Intel AMT configuration profile under Configuration Profiles. It contains:
- an explicit
ACMorCCMcontrol mode - a managed DNS suffix and endpoint-derived hostname
- shared DHCP, shared static IPv4, or dedicated static IPv4 addressing
- firmware consent:
none,kvm, orall - power package
The Intel AMT firmware WebUI remains available on managed endpoints.
Networking is untagged wired IPv4. A Wi-Fi adapter is not required. Ordyn does not configure firmware Wi-Fi, VLAN, 802.1X, or IPv6 settings.
The endpoint's Network interfaces section contains a dedicated Intel AMT interface when AMT support is confirmed. Its IPv4 address is the current management address that the AMT client uses for out-of-band connections. It can differ from the address used by Windows, including while Windows is offline.
Ordyn updates this interface from trusted AMT preflight and inspection results. With shared DHCP, Ordyn can also use a fresh host-interface address when the firmware confirms that AMT shares the same wired MAC address. A net-node IPAM scan can discover a changed address from the AMT MAC while Windows is offline. Ordyn connects to the candidate address and verifies the firmware certificate authority, expected AMT FQDN, credentials, and platform UUID before using it. The interface shows Verified Intel AMT network discovery as its address source after this succeeds.
Users with AMT management permission can edit or clear the current AMT interface address. A later verified network discovery or other trusted observation can replace a manually entered address. A verification result from an older scan does not replace an interface changed after that scan. The AMT interface appears in IPAM but is not used for Wake-on-LAN, PXE, switch-port matching, or host reachability probes.
To discover changed addresses automatically, enable common protocol probes and automatic scans on the managed IPAM network and select a net node on the AMT interface's layer-2 network. Discovery occurs on the next successful scan. If the AMT client is disconnected, verification waits for it to reconnect until the operation expires; a later scan can retry the candidate.
The wired IPv4 modes are:
Shared DHCP: AMT receives its address through DHCP on the shared wired interface.Shared static IPv4: AMT uses the same static IPv4 address as an active host interface on the endpoint.Dedicated static IPv4: AMT uses its own static IPv4 address, which can differ from every host interface address.
Static modes require an endpoint-specific desired network plan containing an IPv4 address, prefix length, gateway, and DNS servers. Configure or remove that plan from the endpoint's Intel AMT overview. The overview displays the current management IPv4 and desired static IPv4 separately.
Saving a desired plan does not claim that firmware already uses it. Ordyn validates the plan against IPAM and includes it in the effective configuration hash. A successful provisioning or configuration remediation applies the static network settings last and only then updates the current Intel AMT interface. Removing a required plan blocks the effective configuration and prevents dispatch until another plan is saved. Audit-only assignments report the blocker without scheduling remediation.
Switching the effective profile to shared DHCP removes a stale desired static plan. The plan is otherwise retained while a profile is temporarily unassigned or disabled and while the endpoint requires recovery, so operators do not lose intended network state during those workflows.
Assign the profile to a tenant, folder, endpoint group, or endpoint and select its behavior:
Audit onlyinspects managed devices and reports drift without provisioning or changing firmware.Remediateprovisions ready unmanaged devices and applies the profile to managed devices.
Use Check now or Remediate now from the endpoint's configuration-profile actions when an immediate result is needed. A managed endpoint is contacted directly through its AMT client, so its Windows agent may be offline. An unmanaged endpoint requires a connected Windows agent for preflight; a successful manual remediation then continues into provisioning. Results appear in the ordinary configuration-profile run history. Recovery-required devices remain blocked until an operator explicitly resumes, rolls back, or deprovisions them, and externally provisioned devices must be adopted first.
Audit only controls automatic behavior. An authorized operator with AMT management permission may still choose Remediate now as an explicit one-time change without modifying the assignment.
When several Intel AMT profiles match an endpoint, Ordyn resolves one effective profile by assignment specificity: endpoint, group, nearest folder, then tenant. A remediate assignment wins over an audit-only assignment at the same scope. Profile fields are not merged.
Disabling the effective Intel AMT configuration profile for an endpoint stops new polling, certificate renewal, health checks, sessions, jobs, and immediate AMT actions while leaving firmware configured. The disabled state continues to apply if assignment precedence selects another Intel AMT profile. Removing a profile or assignment leaves the device configured and marks it unassigned.
Profile changes are evaluated immediately for assigned endpoints. Lifecycle inspection and configuration remediation then follow the selected assignment behavior and the normal retry and recovery safeguards.
Preflight and Provisioning
Run Preflight before provisioning. It is read-only and checks:
- Windows, agent, LocalSystem, MEI, PTHI, and LMS compatibility
- platform UUID and current provisioning/control state
- firmware versions, activation hashes, trust hashes, TEP state, certificate-store, redirection, network, and consent capabilities
- generated-credential activation compatibility and required Intel trust/revocation data
- the tenant's active AMT-client connection
- planned AMT FQDN, AMT interface IPv4, and IPAM conflict state
- configuration profile, certificate authority, and desired static-network-plan prerequisites
Provisioning uses the latest successful preflight result without an arbitrary age limit. Resolve every blocker and run preflight again when the endpoint's state has changed. TEP state reported by the device is retained as diagnostic information and is not used as an activation route.
CCM
CCM uses local host-based configuration and finishes in CCM. Firmware consent is forced to all. CCM is appropriate when local consent and its security trade-offs match the deployment requirements.
ACM
Initial ACM provisioning and CCM-to-ACM transitions complete only through a verified Ordyn-generated setup root. The device must report the selected root fingerprint as trusted and support a permitted activation hash. ACM activation does not fall back to CCM.
Each ACM provisioning attempt uses one activation credential, and recovery continues with that same credential. Ordyn does not retry activation with another credential automatically. Resolve the credential, firmware trust, or DNS-suffix problem before retrying provisioning.
Ordyn selects the operational TLS key profile from the firmware capabilities collected during preflight. AMT 11–14 and AMT 15 versions before 15.0.30.1545 use RSA-2048. AMT 15 beginning with 15.0.30.1545 and supported newer firmware prefer ECDSA P-384 with RSA-2048 available as a fallback.
Static IPv4 may be applied after activation when the selected Intel route requires DHCP during activation. Ordyn applies hostname and network changes last, reconnects, and verifies platform UUID and strict TLS. An ambiguous identity or network result enters recovery_required.
Provisioning is serialized per endpoint. Each attempt receives a monotonic attempt number for recovery evidence. A process or connection interruption resumes from the recorded phase with the original activation credential. If AMT is already in Setup Mode, Resume reconnects through the recorded temporary TLS identity and continues the incomplete setup without starting secure host configuration again.
Firmware Certificates
Open Hardware > Intel AMT > Certificates to inspect the certificates and trust hashes reported by the device. The page has two independently paginated tables. Search, filters, sorting, and pagination are performed by the server.
Provisioning Trustshows the certificate hashes that firmware accepts for ACM activation. Entries identify built-in Intel trust, Ordyn activation credentials, and custom roots installed by another administrator. A normal AMT preflight refreshes this inventory through the Windows agent.Certificate Storeshows the certificates currently installed in the AMT WS-Man certificate store, including subject, issuer, serial number, SHA-256 fingerprint, exact key and signature profile, validity, trust role, access state, and whether Ordyn can associate the entry with a certificate it manages. A normal AMT inspection refreshes it through the assigned AMT client.
Ordyn replaces an inventory only after the device reports a complete, valid snapshot. A failed or partial collection leaves the last complete inventory in place, and the Observed column shows when that retained snapshot was collected. Custom or External means that Ordyn observed the entry but does not claim ownership of it. Routine provisioning, renewal, and remediation do not remove these entries. A confirmed adoption replaces the complete WS-Man certificate store as described below.
Managed entries also show their current renewal state. See Intel AMT Certificates and Renewal for validity periods, automatic maintenance, authority overlap, and recovery after expiry.
Firmware Events
Open Hardware > Intel AMT > Firmware events to review the firmware message and audit records reported by the device. Select Collect firmware events from the endpoint toolbar's Intel AMT menu to request a new collection. Refreshing the table reloads stored records without contacting the device. Repeated records are retained only once, while historical records remain available after later collections.
Some firmware exposes only one of the two logs or can temporarily reject one source. A warning row above the table identifies a partial collection; an error row identifies a collection in which neither log could be read. A partial collection completes with a warning. A collection fails when neither log can be read. Stored rows remain visible in both cases, so the status row distinguishes retained history from records read during the latest collection.
Adoption, Recovery, and Deprovisioning
Detect an External Management Identity
An explicitly requested Inspect first validates the device with its currently configured managed certificate policy. If that connection fails only because the presented certificate has an unknown or self-signed issuer, a different DNS identity, an invalid validity period, or a different leaf fingerprint, Ordyn can use trust on first use (TOFU) for the remainder of that single inspection.
During this fallback, Ordyn observes the certificate at the stored Intel AMT IPv4 address and pins that exact leaf certificate for the authenticated inspection that immediately follows. It does not resolve the AMT name to a different address. The inspection succeeds only when the configured administrator credential is accepted and the firmware reports the endpoint's expected platform UUID and a provisioned CCM or ACM control mode. A connection refusal, timeout, TLS protocol or cipher failure, changed certificate between observation and authentication, rejected password, or different platform identity fails closed without changing ownership.
If the other management environment changed the administrator password, set the endpoint-scoped secret variable hardware.intel_amt.admin_password to the current Intel AMT password before selecting Inspect. This intentionally replaces the credential that Ordyn uses for the inspection. A password change alone is not sufficient evidence of external management, so a rejected credential never causes reclassification.
The observed certificate and its issuer are not promoted into Ordyn's managed trust. Background availability checks, automatic reconciliation, configuration-profile checks, and AMT address verification continue to require their normal managed identity. If the authenticated certificate is not an Ordyn-issued certificate for that endpoint, the inspection changes ownership to external, records the identity drift, and makes Adopt available through the live endpoint update. If it is a known Ordyn certificate, the endpoint remains managed and the certificate-policy drift is scheduled for repair. Inspecting does not change the firmware configuration; adoption remains a separate, confirmed action.
Adopt an Existing Configuration
Use Adopt for an endpoint that is already provisioned in CCM or ACM by another management system. Adoption requires:
- an assigned Intel AMT configuration profile in
Remediatemode - an online compatible Windows agent and connected assigned AMT service client
- a successful preflight that reports the existing provisioned state
- the current Intel AMT
adminpassword
The Intel AMT administrator password is the credential used for remote AMT management. It can differ from the MEBx password used in firmware setup.
Before adoption, set the endpoint-scoped secret variable hardware.intel_amt.admin_password to the current Intel AMT administrator password. The Adopt action remains unavailable until this variable has a value.
Open the endpoint and select Intel AMT > Adopt from the endpoint toolbar. Ordyn verifies the platform identity and control state, replaces the device's WS-Man certificate store, installs its operational configuration and certificate, and applies the network plan through the endpoint's local AMT connection. It then connects directly to the planned IPv4 address on port 16993, using the managed FQDN only for TLS hostname verification, and verifies the exact certificate, platform UUID, and control mode. DNS resolution never replaces the planned IPv4 target. Only after that verification and certificate-store replacement does Ordyn rotate the administrator account to a unique managed password. The existing value remains stored throughout the operation. Ordyn replaces the variable with the newly verified password only after adoption succeeds. If the operation fails or requires recovery, the existing password remains available and the replacement candidate is retained for the authorized recovery path.
Configuration-profile remediation does not take ownership of an external Intel AMT device. Use Adopt first; adoption applies the effective Intel AMT profile while taking ownership, and later configuration drift can use normal remediation.
Adoption preserves the current control mode, ACM provisioning-trust hashes, AMT users, and ACL entries. It removes every mutable certificate, trusted root, and key pair from the WS-Man certificate store, including external server and client certificates, and finishes with only the verified Ordyn server certificate, its installed chain, and its matching firmware key. Certificate-based 802.1X, CIRA, or other firmware configurations that depended on removed client certificates require separate reconfiguration after adoption. Use full deprovisioning and provisioning when users, ACL entries, or ACM provisioning trust must also be replaced.
For a supported device already in the selected CCM or ACM mode, the current administrator password is sufficient for adoption. Same-mode adoption does not need an Ordyn activation root. For existing ACM, the firmware PKI DNS suffix also does not need to match the managed DNS suffix. A setup.bin is required only when the device must enter ACM or transition from CCM to ACM.
Certificates serve different purposes during this workflow:
- The activation root and firmware PKI DNS suffix authorize ACM activation. Existing activation trust remains installed but is not used for same-mode adoption.
- Existing mutable server certificates, client certificates, trusted roots, and their firmware keys are removed during adoption, regardless of which management system created them.
- The Ordyn operational certificate is installed during adoption and must pass strict hostname, certificate-authority, exact-certificate, platform-identity, planned-address, and selected-control-mode verification before adoption succeeds.
When the current external server certificate is required for the authenticated adoption connection, Ordyn retains only that exact certificate and matching firmware key while it removes the rest of the store. After the Ordyn certificate is installed and verified, Ordyn removes the retained external identity and verifies the final store before changing the administrator password.
If adoption is interrupted during certificate-store replacement or certificate installation, Ordyn records the completed stage, generated key, certificate request, certificate, and installed references for recovery. Resume repeats incomplete cleanup safely and reuses recorded certificate material when it is available. If the Ordyn certificate was committed, Resume verifies and reuses that exact certificate with the existing administrator password. For firmware that requires the AMT TLS compatibility connection, it connects to the recorded IPv4 address and verifies the certificate, platform UUID, control mode, certificate reference, and key reference before removing remaining material. It does not request another firmware key when the recorded certificate can be verified. Ordyn then applies any remaining network change through the local connection, verifies the planned IPv4 directly, completes the store replacement and password rotation, and verifies the managed credential.
If preflight or live verification reports a control mode different from the selected same-mode adoption route, an unprovisioned device, or a different platform identity, adoption stops before applying the configuration. A CCM device targeting ACM follows the explicit transition path and must meet the normal activation-root, DNS-suffix, wired-link, and DHCP requirements. Ordyn never changes ACM to CCM automatically.
Reset and Reprovision an Adopted Device
Use the following sequence when the existing AMT configuration must be removed before Ordyn provisions it again:
- Adopt the externally provisioned device and wait until its ownership is
managedand TLS verification succeeds. - Select
Intel AMT>Full deprovisionfrom the endpoint toolbar and confirm the action. - Wait until the endpoint reports provisioning state
unprovisioned. Ordyn disables the effective Intel AMT configuration profile during deprovisioning to prevent automatic reprovisioning. - Open the endpoint's
Configuration Profilestab and enable the Intel AMT profile. - Run
Preflightagain to collect the unprovisioned firmware state and current trust inventory. - Select
Intel AMT>Provision, or runRemediate nowfor the effective Intel AMT configuration profile.
Ordyn cannot partially or fully deprovision an externally managed configuration before adoption. Those actions require the administrator credential and device TLS identity verified during adoption. If the current AMT administrator password is unavailable, use the device's MEBx or OEM recovery workflow to unprovision it locally, then run preflight and provision it with Ordyn.
Recover an Interrupted Operation
If provisioning becomes ambiguous or fails after a possible firmware mutation, ownership changes to recovery_required. A failure that firmware explicitly reports before accepting any change remains a normal failed attempt and can be corrected without recovery. The AMT overview shows recovery guidance, and the endpoint History tab records the failed operation and its current result. Use the endpoint toolbar to choose:
Resumeto continue from a verified safe pointRoll backto undo the incomplete Ordyn setup when supported
Recovery never automatically unprovisions the device.
The Windows agent must remain connected during Resume and Roll back so Ordyn can verify the live platform UUID, provisioning state, and control mode through Intel PTHI. Firmware that requires the AMT TLS compatibility connection is contacted at its recorded IPv4 address using the exact authorized certificate identity. A TLS, certificate, credential, platform-identity, or control-mode mismatch stops recovery without selecting another connection method.
CCM-to-ACM transition requires a dedicated confirmed action and a firmware-reported in-place path. Otherwise, perform a confirmed deprovision and provision in ACM. ACM-to-CCM is never automatic.
Partial and full deprovisioning are available only while live firmware reports a provisioned device in CCM or ACM. A device in Setup Mode must be rolled back first. Ordyn disables management before changing firmware and records a successful result only after the Windows agent verifies that firmware is stably unprovisioned. Configuration-profile removal does not deprovision.
| Action | Firmware result | Data retained by Ordyn |
|---|---|---|
| Partial deprovision | Removes the active AMT configuration and installed certificates. AMT remains enabled and can be provisioned again. The AMT administrator password and provisioning trust are retained. | The verified AMT administrator secret and observed provisioning-trust inventory are retained. Issued device certificates remain in certificate history as retired, while the current firmware certificate inventory is cleared. |
| Full deprovision | Returns AMT provisioning to its factory-unprovisioned state, including removal of configured users, installed certificates, and custom activation trust. AMT remains enabled and can be provisioned again. | The managed AMT administrator secret and current provisioning-trust inventory are removed. Issued device certificates remain in certificate history as retired, while the current firmware certificate inventory is cleared. |
Neither action changes the MEBx password or disables AMT in firmware. Endpoint deprovisioning also does not delete tenant certificate authorities, reusable activation credentials, or the AMT service client's enrollment. Run preflight again before provisioning so Ordyn can collect the current firmware state and trust inventory.
Credentials and Recovery Bundle
Ordyn stores two endpoint-scoped retrievable secret variables for recovery:
- AMT administrator password is the credential Ordyn last verified against the device. During rotation, the bundle also includes the pending candidate until verification succeeds. Editing this variable directly changes only Ordyn's stored value and marks it unverified; use the AMT credential-rotation action to change the firmware credential safely.
- MEBx password is the intended new password written into a per-device
setup.bin. It is recovery evidence rather than proof of the device's current password. See Intel AMT Setup for password fields and preboot keyboard-layout guidance.
An AMT Administrator with permission to reveal secret variable values can download the endpoint's recovery bundle. The download is audited, returned with no-cache headers, and contains plaintext high-value recovery material. Store it in an appropriately protected password vault or encrypted offline location.
The JSON bundle contains endpoint and AMT network identity, current and pending administrator-password candidates, the intended MEBx password, the AMT server certificate and public CA certificate, certificate fingerprints, and expiry. It never contains a certificate-authority private key. Download a fresh bundle after credential or certificate rotation.
A current bundle provides the credentials and device certificates needed to recover or manage a reachable AMT device if the Ordyn environment is lost. Successful recovery still depends on the device retaining that configuration, certificate validity and revocation state, and network reachability.
Deleting an endpoint or tenant terminates active AMT sessions and removes Ordyn AMT records, credentials, certificates, assignments, and setup artifacts. Firmware is left configured. Review the deletion warning and deprovision first when firmware should be cleared.
Immediate Actions and Jobs
Immediate AMT actions target one endpoint and fail immediately when the assigned AMT client is offline. They are not queued for later. Durable AMT job tasks may wait for the client until the normal job deadline.
The endpoint toolbar groups direct actions into a small set of menus:
Powercontains Wake, graceful operating-system shutdown and reboot, plus the Intel AMT power actions supported by the device.Endpointcontains endpoint settings such as agent log severity, service routing, self-service policy, and endpoint editing.Intel AMTappears for supported devices and contains provisioning, adoption, firmware-event collection, credential rotation, one-time boot, recovery, deprovisioning, and recovery-bundle download actions when they apply to the current device state. Use the assigned Intel AMT configuration profile to check, remediate, disable, or enable configuration.Lifecyclecontains certificate renewal, reinstall preparation, suspension, revocation, agent removal, and endpoint deletion.
Unavailable actions are hidden when they do not apply to the device. Temporarily blocked actions remain visible with the reason, such as an offline assigned AMT client. Only the available recovery actions are shown while recovery is required.
Every directly requested AMT operation appears as a row in the endpoint History tab. The row follows the current operation status and shows its failure message when present. Recovery-required and recovery-resolved results also appear in this timeline. The history row remains available after leaving the AMT page.
Available job tasks are:
Inspect Intel AMTRead Intel AMT power stateRun Intel AMT power actionSet Intel AMT one-time bootMount Intel AMT mediaWait for Intel AMT media workflowUnmount Intel AMT media
KVM and SOL are interactive and cannot be job tasks. Job execution requires normal Jobs permission plus AMT Operator or AMT Administrator permission for every target. Media also requires permission to use the selected file or OS image.
Remote Power
| Action | Behavior |
|---|---|
| Power on | Requests the desired on state |
| Shut down gracefully | Requests Intel AMT graceful soft-off and waits up to two minutes for the endpoint to turn off |
| Power off | Requests AMT soft-off/S5 without waiting for the operating system to shut down |
| Reset | Performs a master-bus reset |
| Power cycle | Performs an off-soft power cycle |
The Power menu shows only the actions supported by the device for its current state. Shut down gracefully is available only when firmware advertises the graceful soft-off state. Ordyn sends the selected action once and then reads the power state again. The follow-up reading updates the available power actions immediately. Ordyn does not repeat a power mutation after a timeout. An outcome that cannot be verified is reported as ambiguous.
Graceful shutdown gives the operating system up to two minutes to complete its shutdown. If the device does not reach an off state, Ordyn reports that the request was accepted but could not be confirmed. It does not replace the request with a forced power-off.
If the action completes but the follow-up reading fails, Ordyn shows a warning and keeps the last observed power state and actions until another power-state reading or AMT inspection succeeds. Wake-on-LAN is not used as a fallback.
Power off, graceful shutdown, and power cycle end any active KVM, SOL, or redirected-media session immediately before the power request. The KVM console reports that it closed for the selected power action. New redirection sessions remain unavailable until the power action finishes. Power on, reset, and one-time boot do not automatically end active redirection when firmware permits those operations.
One-Time Boot
One-time boot supports only targets advertised by firmware:
- normal or local disk
- PXE
- optical or redirected media
- BIOS setup
- clear the next-boot override
The setting applies to the next boot only. Ordyn does not manage persistent firmware boot order.
Read-Only Redirected Media
Select Mount image in the KVM console toolbar to mount an Ordyn file or operating-system image in ISO or raw IMG format. The file selector lists only ISO and IMG files whose malware scan completed successfully. Physical drives, writable media, and browser uploads are unsupported.
If the selected image is not yet available at the AMT site, the dialog shows preparation progress and mounts it automatically when preparation finishes. Closing the dialog cancels that automatic mount, but does not cancel preparation. The default maximum image size is 20 GiB; the configured hard limit cannot exceed 100 GiB.
The KVM toolbar shows Preparing while the AMT client downloads and verifies the image, Waiting for consent when firmware requires a code, and Mounted after the endpoint starts reading the attached image. Select Cancel mount while preparation or consent is pending. A failed or cancelled request restores Mount image automatically.
Not detected means the image remains attached, but the endpoint did not start reading it before the discovery deadline. You can still unmount it, and the status changes to Mounted automatically if the endpoint reads it later. If the image remains unavailable, unmount it and retry. Export a support bundle if the problem continues.
A mounted image is attached immediately and can appear as read-only removable media in the running operating system. Mounting does not change the endpoint's boot target or restart it. To boot from the image, keep the mount active, set the next boot target to redirected media, and then reset or power on the endpoint.
Set Unmount automatically after when mounting an image. The default is four hours and the maximum is twelve hours. Mounted media remains active if the KVM window closes. Reopen KVM to see the mounted image and select Unmount image when finished. Unmount redirected media before shutting down or restarting unless you intend to boot from it; some firmware can delay a power transition while redirected media remains attached.
One KVM or SOL session and one redirected-media mount can be active on the same endpoint. A second interactive session or second media mount remains blocked until the corresponding active session ends.
Mount, wait, and unmount also remain available as separate job tasks for unattended workflows and devices where KVM is unavailable. Cancelling a job requests immediate unmount; automatic expiry remains the final cleanup limit. Wait conditions can use:
- endpoint-agent reconnect plus a grace period
- AMT power state
- fixed duration
- explicit manual completion
When firmware requires consent, the task shows waiting for consent. The Windows agent does not read the displayed firmware code.
KVM and SOL
Open KVM or SOL from the Intel AMT menu in the endpoint toolbar. Ordyn opens a dedicated console window and starts the session immediately. The window shows the Ordyn endpoint name, current session state, and remaining time. Supported browsers are current desktop Chrome, Edge, and Firefox. Mobile and unsupported browsers show a blocked-console message. Allow popups for the Ordyn frontend.
The browser connects only to the selected public relay. It does not reach the AMT client or device and never receives AMT credentials. Relay traffic is protected by WSS on each hop. The relay can observe live session content but does not retain, record, sample, export, or send it to error reporting.
The endpoint requires a Relay assignment for KVM and SOL. It uses the nearest configured folder Relay route, then its tenant Relay route. If neither scope has assignments, KVM and SOL are unavailable. A configured route with no connected, compatible Relay service client that has capacity blocks KVM and SOL without using another scope. Configure and inspect these assignments from Service routing on the tenant or endpoint folder. An active KVM or SOL session remains on the Relay selected when it started.
KVM
KVM supports video, keyboard, mouse, fullscreen, and special keys from the top toolbar. Intel AMT KVM does not provide clipboard transfer.
The pointer selector defaults to Auto. Use Relative when the local pointer reaches the edge of the browser before the remote pointer reaches the edge of the display. Click the console to capture the pointer and press Escape to release it. Use Absolute when direct local-to-remote pointer positioning works better for the endpoint.
The KVM toolbar includes the same supported Intel AMT power actions as the endpoint Power menu. A power action that must end redirection closes the console after confirmation and continues in the background. Its final result remains visible in endpoint history.
The remote keyboard selector supports German and US layouts. Each console starts with German selected. Select the layout configured in the remote operating system. Intel AMT emulates US keyboard positions, and Ordyn translates German physical key positions while the KVM display has keyboard focus.
Fit scales the firmware display to the available window. Actual size shows native framebuffer pixels and permits scrolling when the display is larger than the window. Actual size can appear sharper because the browser does not scale the framebuffer. Available color depth and source resolution depend on the device firmware. KVM uses the display configured as the firmware default.
SOL
SOL supports terminal input and output, supported terminal resize, and special control sequences. Ordyn does not retain or offer a terminal transcript.
Consent and session limits
Firmware consent follows the effective configuration profile and the device control mode. A consent wait lasts five minutes and permits at most three failed submissions. Consent values exist only while processing the request and are not stored or logged.
When an immediate operation or interactive session requests firmware consent, Ordyn opens the shared consent dialog. Enter the six-digit code displayed on the endpoint. Closing the dialog keeps the request active. For operations, select Enter consent code on the matching endpoint-history row to reopen it, or select Abort operation to cancel the firmware prompt. For KVM and SOL, use Enter code or End on the session row. Cancelling releases the consent wait as soon as the AMT client confirms the cancellation.
One interactive session can be active per endpoint: either KVM or SOL. One redirected-media mount can run alongside it. Other operators can see the kind, initiator, start, expiry, and permitted termination actions, but never session content.
Each KVM or SOL session has a four-hour maximum lifetime. Ordyn ends the session after 15 minutes without operator keyboard, mouse, terminal input, or an explicit Keep open action. Passive screen and SOL output do not reset idle time. Before idle expiry, the console displays a warning with the Keep open action. Disconnecting, closing, or unloading the window terminates the session sooner. If the remote session closes, the console displays its ended state and offers a retry that starts a fresh session. A disconnected session cannot reconnect; complete firmware consent again if the new session requires it.
Disconnecting or restarting the assigned AMT service client ends its active KVM, SOL, and redirected-media sessions. Ordyn clears the ended session state when the service disconnects or reconnects, so another console or media mount can be started after the service becomes available.
After the console closes, the endpoint toolbar refreshes while the session is ending. KVM or SOL becomes available again when termination completes without requiring a page refresh.
Roles, Audit, and Security
| Role | AMT access |
|---|---|
| AMT Viewer | Read AMT state, evidence, inventory, configuration result, certificate metadata, events, operations, and busy-session metadata |
| AMT Operator | Viewer access plus inspect, power, one-time boot, KVM, SOL, media, consent submission, and termination of own sessions |
| AMT Administrator | Operator access plus configuration profiles, assignments, per-endpoint profile disabling, CA rotation, provisioning, adoption, recovery, credential rotation, mode transition, deprovisioning, and termination of any tenant AMT session |
| Service Operator | Manage AMT clients and activation credentials plus the independently permissioned Relay service, enrollment, and service diagnostics; tenant endpoint control is not included |
AMT operations record the actor, endpoint, requested action, state, and result metadata. Credentials, private keys, consent codes, complete session grants, KVM/SOL content, and media blocks are excluded from normal responses, audit metadata, logs, and support bundles.
Unsupported Capabilities
Ordyn AMT management does not support:
- Linux provisioning or Linux MEI/PTHI management
- AMT-only endpoint creation or active network discovery scans
- Wi-Fi, IPv6, VLAN, or 802.1X provisioning
- CIRA/MPS, TURN, VPN, SOCKS, or generic TCP relay behavior
- direct browser-to-device or browser-to-AMT-client access
- Windows remote desktop control
- KVM/SOL recording, screenshots, transcript retention, file transfer, or clipboard transfer
- persistent boot-order management
- Kerberos or Active Directory AMT authentication
- shared device credentials, bulk secret export, or automatic password rotation
- external operational certificate authorities
- externally issued ACM provisioning certificates and private keys
- TEP voucher acquisition or TEP owner activation
- OEM BIOS, ME firmware, or driver updates
- System Defense, AMT alarm scheduling, or executable secure erase
- automatic forced-power fallback after an unconfirmed graceful shutdown or automatic Wake-on-LAN fallback
- AMT-client high availability or automatic failover
See Intel AMT Infrastructure for AMT client enrollment, network, activation credentials, PKI, and diagnostics. See Relay for public KVM and SOL session transport.