_abednego

updated

1 year ago

_

_abednego

1 Rookie

78 Posts

1

40747

July 24th, 2019 03:00

What does "ME disabled" really mean?

Hello.

I have three old but reliable OptiPlex 780 USFF desktops.  All these desktops have a label inside with a large "3" and the text "ME disabled" on them.

What does this label means?  Is it really referring the the Intel Management Engine being disabled at factory, or just the Intel Active Management Technology?

As you surely know Intel ME and AMT are different, even if the latter requires the former.  I am looking for machines that truly have ME disabled, not just the AMT part.  Has been Intel ME completely disabled on these small desktops?

Thank you!

  • U2CAMEB4ME

    6 Operator

    6245 Posts

    30702

    1

    Posted July 24th, 2019 08:00

    Welcome to the Dell Community @_abednego 

    Suspend Mode:

    Sets the power management suspend mode to:
    S1
    S3 (default)

    NOTE: If the AMT Management Engine (ME) of the system is disabled, the S1 suspend mode is
    unavailable in the system setup.

    Dell OptiPlex 780 Service Manual--Ultra Small Form Factor Computer:

    https://downloads.dell.com/manuals/all-products/esuprt_desktop/esuprt_optiplex_desktop/optiplex-780_service%20manual4_en-us.pdf

    Best regards,

    U2

  • speedstep

    11 Legend

    46969 Posts

    25962

    0

    Posted September 13th, 2020 18:00

    Management Engine INTEL AMT permanently Disabled.

    AMT HECI SOL INTEL VPRO MANAGEMENT

    Once disabled it can never be used again.Once disabled it can never be used again.

    Label   SKU Part Number Description
    Basic Systems Management Mode
    1 vPro
    AMT
    DASH Ready

    310-9491 CU245 Short: Advanced Client Systems Management,w/vPro,OPTI
    Long: Advanced Client Systems Management,with vPro,Dell OptiPlex
    Option Online: Advanced Client Systems Management (w/ vPro)
    MOD MOD,LBL,MGMT,VPRO/AMT/DASH


    1 AMT
    DASH Ready
    310-9494 HP413 Short: Advanced Client Systems Management,w/iAMT,OPTI
    Long: Advanced Client Systems Management,with iAMT,Dell OptiPlex
    Option Online: Advanced Client Systems Management (w/ iAMT)
    MOD MOD,INFO,MGMT,AMT/DASH,OPTI


    2 ASF Only 310-9492 CU377 Short: Basic Client Systems Management,w/ASF,OPTI
    Long: Basic Client Systems Management,with ASF,Dell OptiPlex
    Option Online: Basic Client Systems Management (w/ ASF)
    MOD MOD,INFO,MGMT,ASF ENABLED


    3 ME Disabled 310-9493 XT411
    NN180
    Short: Client Systems Management Disabled,OPTI
    Long: Client Systems Management Disabled, Dell OptiPlex
    Option Online: Client Systems Management Disabled
    MOD MOD,INFO,MGMT,MEBX,DISABLE,OPT
    MOD MOD,INFO,1-WATT,BIOS,OPTI,755



    Deployment Mode
    N/A Disables Remote Configuration 310-9495 CU378 Short: One Touch Provisioning Support,OPTI
    Long: One Touch Provisioning Support, Dell OptiPlex
    Option Online: One Touch Provisioning Support
    MOD MOD,INFO,MGMT,ONE TOUCH CNFG


    2 ASF with AMT option 310-9497 WK835 Short: LEGACY ASF SETTING FOR IAMT,OPTI
    Long: Legacy ASF Setting for iAMT,Dell OptiPlex
    Option Online: Legacy ASF Setting for iAMT
    MOD MOD,INFO,MGMT,ASF ROLL BACK


    4 No TLS * 310-9496 RU572 Short: TLS Encryption Disabled,OPTI
    Long: TLS Encryption Disabled, Dell OptiPlex
    Option Online: TLS Encryption Disabled
    MOD MOD,INFO,MGMT,TLS,DISABLE,OPTI


  • savvy2

    4 Apprentice

    2547 Posts

    30705

    1

    Posted July 24th, 2019 07:00

    I sure cant speak  for labels,

     

    but all that can be turned off in BIOS, if you look, did you first and upgrade BIOS? Freedos method more safe?

    yes disable it , it is bug ridden for sure on old PC.

    ME/AMT BIOS is very complex and with PCs advanced security packages works as team. and  is risky.

    its cute though, tried it 1 time on HP, and found later the w10 software for it is no good,(exploits) and will never be upgraded from my PC with it, so its is gone.

    I think if BIOS PW is off, fully there is no AMT, (my theory)

  • _abednego

    1 Rookie

    78 Posts

    30697

    1

    Posted July 24th, 2019 09:00

    Hi savvy2.

    No.  Intel Management Engine (ME) cannot be disabled in BIOS, only Active Management Technology (AMT) can. There is a huge difference between ME and AMT.  I am talking about the former, the autonomous subsystem that runs inside the Platform Controller Hub (PCH) on most mainboards manufactured in the last decade.

    I fail to see how it can be related to BIOS not being updated. Indeed, the BIOS on these desktops has been updated to its most recent release (A15) using a Dell Real-Mode Kernel bootable USB drive (a Dell RMK bootable drive that only contains COMMAND.COM, DELLBIO.BIN and DELLRMK.BIN plus the O780-A15.EXE executable).

    I know for sure these desktops do not have —and never had— support for AMT on BIOS, nor a hotkey to enter the Management Engine BIOS extension (MEBx).  But —as I said on the first post— AMT is not the problem, ME is.

    Edit: note that Intel ME is a requirement for AMT, but the reverse is not true.  In other words, you cannot have AMT without ME but you can have ME without AMT.  I never though on AMT being a backdoor (at most it can have horrifying bugs like CVE-2017-5689), but ME is another matter.  This engine is running on most processors built in the last decade even if AMT is fully unprovisioned; it is the right place to build a backdoor if the intelligence community wants one.

    Now Dell is selling workstations like the Precision 3431 Desktop with two different non-manageable processor options ("AMT disabled" and "both ME and AMT disabled").  The latter is the right one for someone that cares about security at the hardware level.

  • _abednego

    1 Rookie

    78 Posts

    30696

    0

    Posted July 24th, 2019 10:00

    Hello U2CAMEB4ME.

    That is interesting... so, if there is no S1 power state configurable on the BIOS setup then there is no support for Intel ME?  These are great news, as the BIOS on these desktops never had a "Power Management → Suspend Mode" option at all.

    That's odd, I downloaded that manual some time ago and looked at the BIOS settings.  But, for some reason, I missed the description of the power state configuration.  To be honest, I had spent more time on the Dell OptiPlex 780 Technical Guidebook as it has a more pleasant format and supposedly has the same information about BIOS defaults.  I guess it is time to read more carefully the service manual.

    If someone disagrees please say it loud!  But, as I understand it now, this one is the right answer; as the BIOS setup never had an option to enable the S1 power state it seems not only AMT but also ME have been disabled on factory.  These are fine desktops with the configuration I am looking for.

    Thank you.

  • dubfactor

    2 Posts

    25978

    0

    Posted September 13th, 2020 13:00

    The QR code reads:

    CN0G451FC088737T06YKA0

    20200913_152617.jpg

     

    CN0G451FC088737T06YKA

    https://drive.google.com/file/d/16vOSn9Y9l59n-lW3SWqiWx2ubvuxRYA-/view?usp=drivesdk 

  • XJR8942

    6 Posts

    0

    0

    Posted September 17th, 2023 00:09

    @speedstep​ What program is that in your screenshot? Where did you get it? Will picking option 3 permanently disable the ME? Thanks.

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    0

    1

    Posted September 18th, 2023 01:30

    Speedstep hasn't been on this forum for a year now.  One of our other contributors might answer if they can.

    Meanwhile, the screenshot is the F12 Boot and Diagnostics menu.  Immediately and repeatedly press F12 upon startup.  I've never seen the text in green before.

  • Chino de Oro

    11 Legend

    8458 Posts

    46451 Points

    0

    1

    Posted September 18th, 2023 01:56

    @XJR8942​ , the screenshot from speedstep's post is the first boot screen of a new motherboard replacement, not from a program.

    Selecting option 3 will disable Intel AMT.  It won't disable Intel ME. 

  • bradthetechnut

    9 Technologist

    9649 Posts

    40713 Points

    0

    1

    Posted September 18th, 2023 02:23

    "Selecting option 3 will disable Intel AMT. It won't disable Intel ME."  Why would it be that way?  I'm genuinely thoroughly confused.