Transcription of Intel®EndpointManagement Assistant (Intel®EMA)
1 intel EndpointManagementAssistant( intel EMA)SingleServerInstallationGuideIntel EMAV ersion: : Tuesday,November23, ,andyouruseofthemisgovernedbytheexpressl icenseunderwhichtheywereprovidedtoyou("L icense").UnlesstheLicenseprovidesotherwi se,youmaynotuse,modify,copy,publish,dist ribute,discloseortransmitthissoftwareort herelateddocumentswithoutIntel' ,withnoexpressorimpliedwarranties, , (expressorimplied,byestoppelorotherwise) ,includingwithoutlimitation,theimpliedwa rrantiesofmerchantability,fitnessforapar ticularpurpose,andnon-infringement,aswel lasanywarrantyarisingfromcourseofperform ance,courseofdealing, featuresandbenefitsdependonsystemconfigu rationandmayrequireenabledhardware, ,theIntellogo, PKI (ACL)
2 ChangeIIS EMA ,Modifying, ,Modifying,andDeletingUsers314 PerformingIntel EMAS erverfromBackup385 Appendix: EMAS ingleServerInstallationGuide-Tuesday,Nov ember23,202111 IntroductionIntel EndpointManagementAssistant( intel EMA)isasoftwareapplicationthatprovidesan easywaytomanageIntelvPro platform-baseddevicesinthecloud, :lIntelEMAcanconfigureanduseIntelAMTonIn telvProplatformsforout-of-band,hardware- levelmanagementlIntelEMAcanmanagesystems usingitssoftware-basedagent,whiletheOSis running,onnon-IntelvPro platformsoronIntelvPro platformswhereIntelAMTisnotactivatedlInt elEMAcanbeinstalledonpremisesorintheclou dlYoucanuseIntelEMA sbuilt-inuserinterfaceorcallIntelEMAfunc tionalityfromAPIsThisdocumentdescribesth eproceduretoinstallandconfiguretheIntelE MAserverinafullproductionenvironment.
3 Asimplifiedtutorialinstallationprocedure forlearningpurposesisavailableintheIntel ,configuration,andmanagementoftheIntelEM Aserverasawhole,aswellascreatingTenantus agespaceswithintheIntel ,suchasTenantAdministratorsandAccountMan agersareresponsibleforsettingupandmainta iningtheusers,usergroups,endpointgroups, :Keyconceptssuchasuserroles,tenants,ande ndpointgroupsaredescribedindetailintheIn tel EMAA dministrationandUsageGuide,whichalsoprov idesdetailedinformationaboutthesetupandm aintenanceofIntel ,explainstheconfigurationparameters,andp rovidesdetailedinstallationstepsfortheIn tel EMAserveranditscomponentsisfairlystraigh tforward, ,beforestartingtheprocedure, , , EMAS ingleServerInstallationGuide-Tuesday,Nov ember23,20212lDeterminetheFullyQualified DomainName(FQDN) ,decideifyouwanttouseWindowsauthenticati onmode(recommended,forsecurityreasons)
4 , :byFQDN/hostnameonly;usingFQDN/hostnamef irst,thenIPAddress; ,andtomanagethem, (Kerberos)ornormalaccount(username/passw ord)mode, , ,followITpracticetosetuptheSer-vicePrinc ipleName(SPN) secureportsbydefault(LDAPS secureport636andGlobalCatalogport3269).P reviousversionsofIntelEMA usedthestandardnon-secureLDAP ports(LDAP port389andGlobalCatalogport3268).Ifyouar einstallingIntelEMA , , ,thenafterinstallingIntelEMA,opentheinst allerprogramagain( ,runasadministrator)andselectFile> AdvancedMode,thenclickSettings> SwitchfromLDAPstoLDAP toresettheLDAP portsIntelEMA ,youcanchangetheportsintheWebserversetti ngsontheServerSettingspageintheIntelEMA provisioning, : ,theIntel EMAA gentcanbeinstalledonthefollowingoperatin gsystems:lMicrosoftWindows*7( )lMicrosoftWindows10lMicrosoftWindows11 IntelEMAS ervercanbeinstalledonthefollowingoperati ngsystems.
5 LMicrosoftWindowsServer2012R2(supportwil lendwhenIntelEMA )lMicrosoftWindowsServer2016lMicrosoftWi ndowsServer2019 EMAS ingleServerInstallationGuide-Tuesday,Nov ember23, Xeon Processors,16threads,24 GBRAM,1 , , , ,English-USsystemlocale,andEnglish-USfor mat(matchWindowsdisplaylanguage). *. , , ,configuring,andusingSQL andActiveDirectoryisrequired( ).IMPORTANT: Toachievesecurityin-depth, :lMicrosoftSQLS erver2012,2014,2016,2017,and2019(English -US versiononly) Server2012willnotbesupportedonceIntelEMA Serverisrunningmustbeasupportedoperating systemversionandneedstohaveEnglish-USWin dowsdisplaylanguage,English-USsystemloca le,andEnglish-USformat(matchWindowsdispl aylanguage).
6 SeeSupportedOperatingSystems, (CPU,memory,SSD,etc.)toSQL Server'sresourcesaredynamicallyallocated , ,youmayseeerrormessageslike"Unabletogetd atabaseconnection,allconnectionsarebusy" inthecomponentserverlogfilesinProgramFil es(x86)\ intel \PlatformManager\ "ServiceBroker" ,youwillseewarn-ingstothateffectinthecom ponentserverlogfilesinProgramFiles(x86)\ intel \PlatformMan-ager\ ,ensurethatanSQL accountexistsontheSQL serverthatcanbeusedbytheIntelEMA installertoconnecttotheSQL databaseadministrator(SQL DBA),contacttheSQL DBA ,sinceyouwillbeaskedtospecifytheSQL accountunderSQL ,theSQL EMAS ingleServerInstallationGuide-Tuesday,Nov ember23,20214defaultdatabasecanbeanyexis tingdatabaseontheSQL installercanconfirmthatthespecifiedSQL account/usercancontacttheSQL ,ensurethattheSQLaccountusedintheIntelEM A SQL connectionstringhassysadminrights(tocrea tenewaccountforIIS defaultapplicationpoolidentity)
7 Andhasatleastdbcreatorpermission,whichal lowsittocreate,modify, ,thisaccountmusthavethedatabaselevelrole sdb_owner,db_datawriter, sysadmin rightisneededinordertocreatethenewuser IISAPPPOOL\\DefaultAppPool\ fortheSQLserver(ifitdoesnotexist).Ifitex istsalreadyoryoudonotusethataccountforth eIISapplicationpooloftheIntelEMAwebsite, thentheroleneededduringinstallationis dbcreator , sysadmin or dbcreator "SUBSCRIBEQUERYNOTIFICATIONS"totheuserof IntelEMA : Ifyoudonotgrant"sysadmin"rightstotheSQL connectionaccount,theinstall-ationwillst illcompletesuccessfully, "sysadmin"rightstotheSQL connectionaccount,youMUST manuallycreatethisuserontheSQL serveraftertheinstallationcompletesinord erforIntelEMA usesMicrosoftInternetInformationServer(I IS).
8 UsethelatestIIS8, , ,IntelEMAwillsetupthewebsitesettingtorem ovetheIISserverversionfromtheresponsehea der,theHSTS header,thecookieSameSitestrict, , :IfIISisalreadyinstalled,ensurethatallau thenticationmethodsaredisabledexceptfor Anonymous and Windows (onlythosetwoshouldbeenabled). PKI CertificateIntelAMTA dminControlMode(ACM) , (thisistheuniqueIntelAMTOID). intel EMAS ingleServerInstallationGuide-Tuesday,Nov ember23, ,theIntelEMA ,youmustspecifythevalue(eitherhostnameor IPaddress) , , ,ifusingActiveDirectory,ensureallcompute rs(includingthecomputerhostingtheloadbal ancer) ,theAJAX serverandManageabilityserverwillestablis haTCPconnection(locallyorremotely) (CIRA).
9 ,console, EMAS ingleServerInstallationGuide-Tuesday,Nov ember23, , "Appendix-ModifyingCom-ponentServerSetti ngs"onpage , "Appendix-ModifyingComponentServerSettin gs"onpage , "Appendix-ModifyingComponentServerSettin gs"onpage , "Appendix-ModifyingComponentServerSettin gs"onpage (secure/non-secure)3269/3268 Thesecure(3269)andnon-secure(3268) ,whichitusestocreateoneormoreMeshSetting sCertificatesthatarestoredintheLocalMach ine\ certificates(EmaMtlsXXX)fortheTCP-TLScom municationsbetweentheIntelEMA componentservers(Ajax,Swarm,Manageabilit y,Web).
10 TheyarestoredintheLocalMachine\ ,thereisnowaytomakeIntel ,afterinstallingtheIntelEMAserver(oreach serverinadistributedenvironment),itisstr onglyrecommendedthatyouperformthefollowi ngsteps:lBackupIntelEMAdatabase(thisshou ldalsobedoneperiodically,notjustafterset up).lBackuptheMeshSettingsCertificatewhi chisstoredintheLocalMachine\ EMAS ingleServerInstallationGuide-Tuesday,Nov ember23, (ACL)forKeyConfigurationFilesAftertheInt elEMAserverinstallation,youshouldmodifyt heACLtolimitaccesstothefollowingfiles\fo lders:l[IntelEMAwebsiterootfolder( ,C:\inetpub\wwwroot)]\ [IntelEMAserverinstallationfolder( ,C:\ProgramFiles(x86)\ intel \PlatformMana ger)]\PlatformManagerServer\ [IntelEMAserverinstallationfolder( ,C.)]