Skip to content

Intel AMT Setup

Intel AMT Setup provides the setup.bin files used to seed an Ordyn-generated activation root in Intel firmware.

Open Software > Intel AMT Setup.

Setup Artifacts

The page lists setup artifacts from tenants you are allowed to view.

Select Generate setup.bin, choose the tenant and an Ordyn-generated activation credential, and then choose an artifact kind. The artifact always uses the credential's DNS suffix. ECC P-384 is the recommended certificate profile for compatible firmware. Ordyn's AMT 11–13 compatibility workflow uses the RSA-2048/SHA-256 activation profile.

For an AMT 11–13 device that must enter ACM or transition from CCM to ACM, apply a setup artifact from an RSA-2048/SHA-256 activation credential before provisioning. The firmware must report that root as trusted, and its configured DNS suffix must match the activation credential and Intel AMT configuration profile. CCM provisioning does not use an activation credential.

An Ordyn setup.bin is not required to adopt a supported device that is already provisioned in ACM. Adoption uses the current Intel AMT administrator password, preserves the device's existing activation trust, and installs an Ordyn operational TLS certificate. The firmware PKI DNS suffix does not need to match the managed suffix for this same-mode adoption.

Creating the RSA credential does not add its trust to firmware. If no active, valid, unexpired RSA credential has a matching trusted root and DNS suffix, ACM provisioning stops without changing the firmware.

The setup file contains the public activation trust required by firmware. Ordyn keeps a separate activation authority for each tenant and activation profile. The authority is valid for 15 years, while each activation credential's provisioning certificate is valid for five years. Both are visible under Administration > Certificate Authorities; the provisioning certificate appears in the authority's Certificates tab.

  • Reusable trust-only contains the activation root without an MEBx password. Use it where firmware accepts password-free trust seeding.
  • Per-device recovery is bound to one endpoint and includes the current and new MEBx passwords. It expires after 24 hours and can be downloaded once.

Treat every downloaded artifact as a credential. Keep it on controlled media and remove it after use.

Externally issued provisioning certificate chains and existing TEP owner identities cannot be used to generate an Ordyn setup artifact.

MEBx Passwords

Generating a per-device artifact requires two password fields:

FieldValue to enter
Current MEBx passwordThe password that Intel MEBx currently accepts. Enter admin when the factory-default password has not been changed. For a customized device, enter its current MEBx or CSME physical-access password. This can differ from the Intel AMT admin password used for remote connections.
New MEBx passwordThe password Intel MEBx should store after accepting the file. Enter the current customized password again to preserve it, or enter a different password. When the current password is the factory default admin, the new password must be changed. The value must contain upper-case, lower-case, numeric, and special characters and be 8–32 characters long.

Both values are embedded in the generated file. Ordyn stores the intended new MEBx password as a retrievable secret variable on the selected endpoint.

Preboot keyboard layout

Intel MEBx commonly interprets the keyboard as a US layout, independently of the Windows keyboard layout. The setup.bin file contains literal characters rather than physical key positions.

If the current password was originally entered in MEBx with a non-US keyboard, enter the characters that the US layout assigned to those physical keys. For example, German QWERTZ keyboards swap the physical Y and Z positions. A password remembered with Y can therefore require Z in the Current MEBx password field, and vice versa. Check other layout-dependent symbols as well.

Logging in manually with the same physical keys can succeed even when the remembered text differs from the characters stored by MEBx. For a new password, prefer characters whose US-layout positions can be reproduced reliably.

If firmware reports Intel ME login with current password failed, confirm that the password works in MEBx and then check the preboot keyboard mapping. Generate and download a fresh per-device artifact before retrying, and replace the previous file on the USB drive.

See Intel AMT Infrastructure for activation credential management and Intel AMT Endpoint Management for provisioning and recovery.