IT@ White Paper Intel IT IT Business Value Employee Productivity and IT Efficiency October 2010

Achieving Long-term Business Value with Intel® vPro™

Executive Overview We see Intel vPro technology Recognizing Intel® vPro™ technology’s significant business value, Intel IT made a as a core capability for strategic decision three years ago to standardize our computing platform on PCs— both and desktop—with Intel® Core™ vPro™ processors. PCs equipped with improving system defense, Intel Core vPro processors include a variety of that enhance IT and asset discovery, remote builds, end-user efficiency, including Intel® Active Management Technology (Intel® AMT), virtualized client usages, and Intel® Virtualization Technology for Directed I/O (Intel® VT-d), Intel® Virtualization device-independent computing. Technology (Intel® VT-x), Intel® Trusted Execution Technology (Intel® TXT), and Intel® Anti-Theft Technology (Intel® AT). These technologies can help meet our most critical challenges—boosting employee productivity, enhancing information security, and improving IT efficiency and business continuity.

We are already benefitting from this decision. • Remote diagnosis/remote repair In particular, some user segments employ • Remote diagnosis/local repair Intel VT-d and Intel VT-x to enhance high- • Remote configuration performance client computing support of multiple OS environments, and we’ll be rolling We estimate we will achieve savings of USD out remote PC management using Intel AMT 500,000 per year from Intel vPro technology’s to 95 percent of our user base by early 2011. remote repair and management capabilities.

At the root of our successful roll out of Intel For other Intel vPro technology features, vPro technology is a methodical implementation such as Intel TXT and Intel AT, we are still plan that has prepared our infrastructure investigating how these capabilities can meet to take advantage of the technology—very our business requirements. We continue to similar to our approach to implementing other actively develop and test use cases and plan Matt Bodin major technological changes, such as wireless pilot projects. computing. We have also developed a set of IT IT Support Engineer, Intel IT We see Intel vPro technology as a core best practices for deploying and provisioning capability for improving system defense, Dave Buchholz Intel vPro technology, and have worked closely asset discovery, remote builds, virtualized Principal Engineer, Intel IT with Intel product groups to help define and client usages, and device-independent refine each of Intel vPro technology’s features computing. By provisioning Intel vPro Frank Engelman so that they address core IT and business needs. Pathfinding Technologist, Intel IT technology across our enterprise, we We have identified several use cases that offer anticipate enhanced user productivity and Dennis Morgan the best long-term return on investment (ROI). reduced IT costs due to fewer service calls Security Strategist, Intel IT These use cases include: and faster response times. IT@Intel White Paper Achieving Long-term Business Value with Intel® vPro™ Technology

Contents BACKGROUND IMPLEMENTING

Executive Overview...... 1 Intel IT’s mission is to use IT INTEL® vPRO™ investment to support Intel’s growth TECHNOLOGY IN OUR Background...... 2 and create value for our business. Our organization is accountable for ENVIRONMENT Implementing boosting employee productivity, To create an infrastructure that supports Intel® vPro™ Technology in the capabilities of Intel vPro technology, Our Environment ...... 2 safeguarding data and intellectual property, and improving IT we designed an implementation plan, Initial Planning Process...... 2 efficiency and business continuity. identified the most valuable use cases, Developing a Use Case Roadmap...... 3 We use technology to manage developed a use case implementation Changing Our Support Processes...... 3 our environment more efficiently roadmap, adjusted our support Refining Our Intel vPro Technology so we can focus our resources on processes, and upgraded our PC Management Console...... 3 innovation. management console.

Using Intel vPro Technology ...... 4 Intel’s worldwide computing environment This methodical approach enables us to Enabling Multiple OS includes more than 100,000 PCs. At Intel, gain the most business value from each Environments on a PC...... 5 as at most companies, managing and capability and is very similar to our approach Enabling Better Remote securing these PCs consumes considerable to implementing other major technological Management of PCs ...... 5 IT resources. To increase our ability to changes, such as wireless computing. Investigating Other Intel vPro maintain, manage, and protect PCs while Technology Capabilities...... 6 driving down management costs, three years Initial Planning Process Best Practices for Deploying and ago we engaged in a multi-year initiative Our initial planning process for introducing Provisioning Intel vPro Technology.....7 to implement Intel® vPro™ technology Intel vPro technology into our environment throughout our environment. Intel vPro Major Decision Points...... 7 included three elements: architecture, technology, a hardware-based capability engineering, and operations. Gaining Implementation Experience...7 built into desktop and laptop PCs, enables Readying Our Infrastructure...... 7 us to perform remotely many functions ARCHITECTURE Conclusion...... 8 that previously required on-site support. It To integrate our client manageability solution is an underlying capability that we can use into our business strategy, capabilities for incident resolution, asset discovery, and roadmap, and governance framework, we increasing enterprise security. considered future client hardware and software solutions; emerging technologies Implementing a solution that significantly and computing models, such as virtualization transforms the way we manage and support and streaming applications; and data our PC fleet involves more than simply center trends that could impact our client acquiring and provisioning machines that management infrastructure. include the technology. As with wireless IT@INTEL technology, we have taken a measured, ENGINEERING The IT@Intel program connects IT methodical approach to launching Intel vPro Our engineering teams defined the architecture professionals around the world with their technology in our environment, introducing peers inside our organization – sharing and assessed technical requirements in terms capable hardware as well as the infrastructure lessons learned, methods and strategies. of infrastructure, applications, platforms, and to take advantage of it. As part of our Our goal is simple: Share Intel IT best provisioning processes. They also integrated standard PC refresh cycle, we have been practices that create business value and the new solution with existing security deploying and provisioning PCs with Intel vPro make IT a competitive advantage. Visit measures to help ensure secure client technology, and we expect 95 percent of our us today at www.intel.com/IT or contact management across the enterprise. your local Intel representative if you’d fleet to be capable by early 2011. like to learn more.

2 www.intel.com/IT Achieving Long-term Business Value with Intel® vPro™ Technology IT@Intel White Paper

Origins of Intel® vPro™ Technology Many of the ideas around Intel vPro technology—and the engineers that helped to deliver this technology—first started in Intel’s own IT organization. Intel saw the value of embedding technologies in business platforms that could help IT shops meet their challenges and requirements. In order to plan, design, and create these technologies, Intel formed a new group with some of Intel IT’s key engineers and architects to focus on these new, embedded capabilities. Today Intel IT continues to work closely with that Intel business unit, as we continue to evaluate technologies, provide input, and help influence the final products that many IT shops use today.

OPERATIONS Currently, we are using Intel vPro technology • Processes. All new processes had to be To transition from provisioning Intel vPro on both laptop and desktop PCs in the aligned with the Information Technology technology to using it to achieve business following use cases: Service Management processes we were already using. value, we developed an adoption strategy • Remote diagnosis/remote repair. A PC that would help us achieve long-term return on that is inoperable due to a software issue, • Scripts. Pre-written scripts helped agents investment (ROI) and a smooth and successful such as a missing or corrupt system file, can talk through the steps required for using Intel implementation. Our approach included be diagnosed and repaired remotely, with vPro technology to resolve each incident. application and technology layers as well as no need for a technician to physically touch • Tools. In some cases we needed to business and data layers. the machine. This approach is much faster, develop new tools, such as a provisioning less costly, and less disruptive to the user. status tool that identifies whether a user’s Developing a Use Case • Remote diagnosis/local repair. A PC with system is manageable using Intel vPro Roadmap a failed hardware component, such as a technology. In other cases we needed to Rather than trying to maximize our short- hard drive, can be diagnosed remotely, modify existing tools, such as our incident term returns, we identified and implemented and the depot can be notified in advance management tool, which needed to be able use cases that delivered meaningful value of specific parts requirements. This can to capture data for Intel vPro technology- with minimal effort. By initially restricting our significantly reduce the mean time to repair. related use cases. implementation to a handful of use cases, we In addition to training our support agents to could give our support agents and end-users • Remote configuration. A PC requiring a use Intel vPro technology to respond remotely time to get used to the new capabilities and BIOS update, such as a hard drive password to service requests, we also wanted them processes, rather than overwhelming them update or other pre-OS state configuration to act as an extension of our product team with too much change all at once. change, can be diagnosed and resolved remotely. Again, this approach is much faster, by identifying new ways to use Intel vPro Our use case implementation methodology less costly, and less disruptive to users. technology. We encouraged support agents included the following steps: to think in new ways, and we provided We have several additional use cases incentives for coming up with new ideas. 1. Identifying the highest-priority planned, including system defense, asset use cases. management and inventory, off-campus 2. Performing ROI analysis. remote repair, Keyboard-Video-Mouse (KVM) Refining Our Intel vPro Remote Control, and . Technology Management 3. Building a use case implementation Console roadmap. Changing Our Support In 2007, when we first began testing 4. Developing future process flows for Processes Intel vPro technology, we needed to the new use cases. We had to define new processes, create identify a management console that best 5. Performing a gap analysis for each use detailed scripts for handling specific fit our needs, integrating with our existing case to identify the changes required incidents and service requests, and develop PC management roadmap and with our for implementation. or modify tools. computing environment. We chose one based

www.intel.com/IT 3 IT@Intel White Paper Achieving Long-term Business Value with Intel® vPro™ Technology

Overview of Intel® vPro™ Technology A component of Intel® Core® vPro™ processors, Intel® vPro™ technology is a combination of processor technologies, hardware enhancements, management features, and security technologies that allow remote access to the PC—including monitoring, maintenance, and management—independently of the state of the OS or power state of the PC. Table 1 summarizes many of the capabilities of Intel vPro technology and the business benefit of each feature.1

Table 1. Intel® vPro™ Technology Features and Benefits

Business Need Feature Benefit • Reduce IT costs Intel® Active Management Technology • Reduces costly desk-side support visits, speeds diagnosis and • Improve business continuity (Intel® AMT), including Keyboard-Video- repair times, and enables remote, out-of-band management of Mouse (KVM) Remote Control wired and wireless PCs even when the OS is non-functional. • Increase employee productivity • Allows Service Desk technicians to remotely manage PCs using a • Support highly mobile PC fleet management console. • Improve information Intel® Anti-Theft Technology • Protects valuable enterprise data and intellectual property, as well and data security (Intel® AT) as the hardware itself, by detecting theft and disabling a laptop if it is lost or stolen. • Allows remote disabling of a PC, as well as remote re-activation. • Decrease security threats Intel® Trusted Execution Technology • Enhances platform security by protecting a laptop against and malware (Intel® TXT) software-based attacks and protecting the confidentiality and integrity of data stored or created on the system. • Allows applications to run within their own space, protected from all other software on the system. • Support service flexibility Intel® Virtualization Technology for • Provides greater flexibility and maximum system utilization and IT consumerization Directed I/O (Intel® VT-d) and Intel® by consolidating multiple environments onto a single server, • Improve employee productivity Virtualization Technology (Intel® VT-x) workstation, or PC. • Enables simplified resource management, greater system reliability, and lower hardware acquisition costs, and is the foundation of a virtualized client roadmap in IT.

1 See also “The All New 2010 Intel® Core™ vPro™ Processor Family: Intelligence that Adapts to Your Needs”. Intel Corporation. January 2010. http://download.intel.com/products/vpro/ whitepaper/crossclient.pdf

on its flexible support for our existing toolset security, authentication, and stability issues. provisioning. These changes enable us to use as well as for other uses in the enterprise. For example, a laptop with a wireless automated, zero-touch provisioning from the connection changes its location and IP server side for the majority of our user base. At first, we provisioned only desktop PCs using addresses many times per day. the management console. In 2008, we created an automated remote provisioning-on-demand We are constantly improving our provisioning tool that lab technicians can use during PC process to address changing business USING INTEL vPRO builds for both laptop and desktop PCs. needs. For example, during 2010, we changed our management console, which TECHNOLOGY Additionally, our initial provisioning process required us to re-provision our entire PC could take place only over hard-wired LANs. We have conducted proofs of concept fleet. We also upgraded the tool to include However, approximately 80 percent of Intel’s (PoCs) to test select Intel vPro scheduled PC refreshes, in order to release workforce uses laptop PCs with wireless technology capabilities, and we machines that are already provisioned. To connections to the network. It was imperative are currently using a number of accommodate wireless network connections, to be able to use Intel vPro technology to these capabilities in our production we also developed a tool that identifies provision and manage these mobile business environment. We are still in the when a machine is connecting to LAN, PCs as well. However, managing clients over preliminary phase of investigation for even momentarily, and immediately triggers a wireless network adds complexity including other product features.

4 www.intel.com/IT Achieving Long-term Business Value with Intel® vPro™ Technology IT@Intel White Paper

Enabling Multiple OS Environments on a PC Intel® Active Management Technology PC Deployment Cycle We have standardized our fleet on mobile business PCs based on Intel® Core™ i5 vPro™ Year 1 Year 2 Years 3 and 4 processors; some will soon use Intel® Core™ Plan, Pilot Activate, Extend Extend Deployment Deployment Deployment i7 vPro™ processors. These systems include Intel® Virtualization Technology. Virtualization Full 0-30% 30-60% 100% solutions enhanced by Intel vPro technology Production Implementation Implementation Implementation Use enable a platform to run multiple OSs and applications as independent virtual machines. This allows one computer system to function as multiple virtual systems. We are here For some user segments, we are using Type-2 virtualization supplied by Intel® Virtualization Goal: 95% capable by early 2011 Technology for Directed I/O (Intel® VT-d) and Intel® Virtualization Technology (Intel® VT-x) to support a mixed Linux* and Figure 1. We have taken a methodical, multi-year approach to implementing Intel® Active Management Technology into our environment. Windows* environment. In this scenario, the hypervisor runs on the main OS, and a We plan to provision Intel AMT on 95 percent users; we then anticipate rolling this feature secondary guest OS runs on top of the main of our entire PC fleet—both and out to production. host OS. With support from the processor, desktops—by early 2011; the remaining 5 chipset, BIOS, and enabling software, Intel percent includes some lab PCs and older REMOTE DIAGNOSIS AND REPAIR VT-x and Intel VT-d improve traditional systems for which Intel vPro technology Keyboard-Video-Mouse (KVM) Remote software-based virtualization by providing is not appropriate. At that time, we will Control is another feature of Intel AMT that more streamlined software stacks and “near- have identified all Intel AMT use cases we plan to use. KVM Remote Control can native” performance characteristics. and developed a use-case implementation give our technicians full control of users’ By using Intel VT-x and Intel VT-d, we are roadmap. Figure 1 illustrates our methodical computers along with the ability to see what able to consolidate multiple environments approach to implementing Intel AMT. is on the monitor—even if the OS crashes. We have developed several use cases where onto a single PC, thereby reducing our REMOTE DISK ENCRYPTION hardware acquisition costs. Also, with PASSPHRASE RESET we can take advantage of KVM Remote Intel vPro technology enabled on these client Control, and anticipate KVM Remote Control We are currently conducting a PoC to further PCs, we have found that they perform up to will significantly reduce the time Service evaluate Intel AMT’s disk encryption passphrase 11 percent faster.2 Desk technicians spend solving some of the reset capability and its integration into the common service calls. We estimate we will web portal of support tools used by Service achieve USD 500,000 per year in savings Enabling Better Remote Desk technicians. So far, the results have Management of PCs from Intel vPro technology’s remote repair been very positive—Service Desk technicians and management capabilities. Intel® Active Management Technology are reporting that Intel AMT has reduced (Intel® AMT) enables us to remotely manage customer interaction time from 45 minutes REMOTE OS UPGRADES PCs, including diagnosis, repair, and shutdown, to approximately six minutes on average. This Intel vPro technology’s remote management thereby reducing the number of costly desk- represents a significant potential for support capabilities are also invaluable during OS side support visits from IT technicians. This cost reduction, since, of the encryption-related upgrades. We are in the midst of a major OS remote management is possible even for PCs calls the Service Desk receives, about sixty upgrade to 7* and plan with encrypted hard drives. percent are due to forgotten passphrases. to use Intel vPro technology to deliver the new OS remotely and to empower users to 2 “Delivering Virtualization Benefits By Refreshing Client Once the PoC concludes, we will engage PCs.” Intel Corporation. July 2008. in a two-week evaluation with production rebuild their own systems.

www.intel.com/IT 5 IT@Intel White Paper Achieving Long-term Business Value with Intel® vPro™ Technology

REMOTE TRAINING ROOM SUPPORT Even in the case of an exiting employee who • Splitting multiple NICs across multiple We also conducted a pilot project in our remote steals a laptop and therefore knows the containers. training rooms that demonstrated how Intel encryption keys, Intel AT enables IT technicians • Assigning resources such as compute AMT can reduce support costs for desktop to disable the laptop remotely and prevent and memory across separate computing 3 PCs. We used Intel vPro technology, along unauthorized access to the data on the laptop. environments. with ISV management software, to address Our initial evaluation of Intel AT indicates that • Assigning audio and video devices to management and performance challenges Intel AT will improve our ability to protect virtual containers to facilitate collaboration. across Intel’s geographically dispersed training company-owned laptops as well as data and • Besides cutting hardware acquisition rooms. We remotely performed rebuilds, intellectual property. We are now conducting a costs, since one machine can take the installs, and security updates that previously higher-level PoC. In this PoC, we are working with place of several, hardware-assisted required on-site support. The pilot project our encryption supplier to test how seamlessly virtualization also enhances system results indicated that we could expect a 65 Intel AT and our encryption software operate. performance and improves security to 75 percent reduction in technician time Our goal is for a Service Desk technician to be by isolating multiple environments on spent per remote software install. We also able to mark a system as lost or stolen when a single PC. In addition, we hope that anticipate other benefits, such as running more a user calls to report a misplaced or stolen PC; this approach to virtualization will demanding applications and using training when the PC next connects to the network or lead to better support models for IT rooms more efficiently. This pilot showed a to the Internet, a poison pill will waiting for the consumerization, where users access 150 percent ROI in its second year, as well system, automatically disabling it. And, if the corporate data with their own devices. as an opportunity to eliminate 50 percent of stolen PC fails to connect to the network within remaining desk-side visits.4 a specific period of time, it enters a “stolen” SECURITY SOLUTIONS state, and the user has to call the Service Desk Intel vPro technology delivers the ability to Investigating Other Intel vPro for a recovery token. Technology Capabilities securely manage PCs over networks, and Currently the PoC includes Intel users across also provides an infrastructure and a set of Intel vPro technology offers several other the United States; future phases will include capabilities that can be used to implement features that we are still investigating, worldwide and external users. a broad range of additional management including Intel® Anti-Theft Technology and security functions. With this in mind, we (Intel® AT), Intel® Trusted Execution Technology HARDWARE-ASSISTED VIRTUALIZATION identified three security use cases that we (Intel® TXT), and security solutions. Although we are already using Intel VT-x and could implement using Intel vPro technology: Intel VT-d in a Type-2 virtualization environment, THEFT DETERRENCE • e-Discovery and investigations we are further evaluating these features Each year, 2 million laptop PCs are stolen, along with Intel TXT in a Type-1 hypervisor • Data protection and loss prevention and 97 percent of these are never environment, where the hypervisor runs directly • System health and updates recovered.5 This represents a huge risk to on the hardware, instead of on the main OS. enterprises in terms of lost hardware and, With Intel vPro technology, we can perform We plan to conduct a PoC later this year using more importantly, lost data and intellectual each of these security use cases remotely these technologies across 100 to 150 clients property. Intel AT can help detect theft and using features such as remote, redirected dispersed throughout different user segments. disable a laptop if it is lost or stolen. boot; console redirect; and agent presence In this PoC, we will be using these technologies checking. This could deliver benefits at a lower level, providing multiple OSs on such as fewer labor-intensive desk-side a platform but completely isolated from each visits, increased security, and greater user 3 “Managing Training Rooms with Intel® vPro™ Processor other, much like the virtualization environment productivity. We successfully conducted lab Technology.” Intel Corporation. April 2007. in today’s server platforms. We anticipate that tests to validate each use case, and we plan 4 “Reducing IT Resource Needs and Service Costs through Intel® Core™ 2 Processor with vPro™ Technology.” Intel the PoC will illustrate benefits in several areas to further investigate these use cases for Corporation. 2008. of client computing: enterprise deployment.6 5 Evers, Joris. “Getting over laptop loss.” CNET News. June • Assigning network interface cards (NICs) to 30, 2006. http://news.cnet.com/Getting-over-laptop- 6 “New Security Solutions Using Intel® vPro™ Technology.” loss/2100-1044_3-6089921.html corporate virtual containers. Intel Corporation. February 2009.

6 www.intel.com/IT Achieving Long-term Business Value with Intel® vPro™ Technology IT@Intel White Paper

BEST PRACTICES pilot project team to include infrastructure We also considered waiting to upgrade our owners. In this way, we helped ensure management tools and processes until we FOR DEPLOYING the infrastructure, such as the Domain had a large pool of provisioned systems. AND PROVISIONING Name System (DNS), was ready to support However, after closer analysis, we realized we INTEL vPRO TECHNOLOGY Intel vPro technology and wouldn’t become could achieve significant ROI by upgrading our an implementation bottleneck. tools and processes earlier rather than later. Intel vPro technology’s set of By taking this approach, our support teams capabilities has a far-reaching • Provisioning decisions. We learned that it is have gained experience with the new tools, impact on our infrastructure and most efficient to “touch” a system only once. and we expect to see our returns increase processes. To successfully manage the We now deploy machines with Intel vPro dramatically as we adopt additional use cases. introduction of the technology into technology activated. Remote, automated our environment, we have developed a provisioning is the most cost-effective Over the last three years, as we have series of best practices. provisioning method, as is provisioning implemented Intel vPro technology in our systems during scheduled PC refresh. enterprise, we have worked closely with Intel In particular, we made several critical decisions • Use case selection. We learned that business groups to develop new use cases and very early in the deployment and provisioning simple, reliable use cases provided the discover ways we can use the technology for stage. Also, as we continued to deploy and best results in terms of ROI and technology more than just PC management. As a result, provision Intel vPro technology, our service adoption. We also learned that involving the technology now also includes features technicians gained valuable experience. the operations team at the beginning of that enhance employee productivity and Finally, we also made some changes to our the use case selection process enabled address major IT concerns, such as information infrastructure to help ensure it could support us to identify the most critical areas and security and support for client virtualization. and benefit from Intel vPro technology. existing gaps between the use case and Computing platform choice, development of current capabilities. pilot projects, provisioning decisions, and use Major Decision Points • Management console selection. We case selection are all important areas in which We made several strategic decisions prior selected a management console that we achieved key learnings. to deploying and provisioning Intel vPro could support our Intel vPro technology technology that enabled us to gain the most provisioning process, as well as integrate Readying Our Infrastructure business value from each capability. seamlessly into our existing infrastructure Our DNS is very large—more than 120,000 • Computing platform choice. Before and processes. systems. Because of this complexity, the DNS provisioning any capabilities, we needed As we continue with full-production refreshes only about every 15 minutes. But to make sure our PC fleet could support implementation, we can benefit from these with the advent of Intel vPro technology, we Intel vPro technology. Three years ago, decisions to maximize the business value we discovered this was not adequate—if a user we standardized on desktop and laptop derive from Intel vPro technology. called the Service Desk, we might not be able to PCs equipped with Intel Core vPro locate and communicate with the user’s PC for processors, deployed as a part of our Gaining Implementation a significant length of time. To circumvent this standard refresh cadence. As we enable Experience problem, we used several different OS-specific specific Intel vPro technology features, protocols, separate from the DNS and HTTP We have modified our practices since we first our client refresh cycle prepares our protocols, to help identify and locate PCs. began to implement Intel vPro technology in enterprise to use these features. our environment in 2007. At that time, we Intel vPro technology also requires a public • Pilot project development. Pilot projects deployed the technology in our PC standard key infrastructure (PKI), and we needed provide a safe zone for learning how to build but did not immediately provision, to address several PKI issues, including use and support a new technology, and or activate, the technology. However, we settings, security certificates, and help ensure the technology fully integrates discovered this approach was inefficient disk encryption passphrases. We needed with the computing infrastructure. When and required us to “touch” a PC twice, which to enable solutions to these issues not planning pilot projects for Intel vPro increased costs. We now actively provision only across the hard-wired LAN, but on our technology features, we expanded the systems when we deploy new hardware. wireless LAN as well.

www.intel.com/IT 7 CONCLUSION the time Service Desk technicians practices for deploying and provisioning spend helping users reset their disk Intel vPro technology across the enterprise. As With its hardware-assisted manageability, encryption passphrase from more we continue to develop and test additional use security, and virtualization features, than 25 minutes to about six minutes. cases, we will be able to further benefit from Intel vPro technology can boost employee Another PoC that involved using Intel Intel vPro technology’s capabilities. productivity, enhance information AMT to manage desktop PCs in remote security, and improve IT efficiency and classrooms suggested that Intel vPro business continuity. By early 2011, we technology could reduce on-site support plan to deploy and provision Intel vPro requirements. Overall, we anticipate FOR MORE INFORMATION technology to 95 percent of our use base. savings of USD 500,000 annually from “3 Use Cases with Intel® vPro™ Technology” Intel vPro technology’s remote repair and video www.intel.com/it/client.htm Already, our PoCs have demonstrated management capabilities. that Intel vPro technology can provide “Evaluating Hardware-based Keyboard- measureable improvements in system Because it represents a major shift in Video-Mouse (KVM) Remote Control.” performance and has the potential to technology, similar to the advent of wireless http://download.intel.com/it/pdf/Evaluating_ substantially reduce IT support costs. computing, we realized early on that HW-based_KVM_Remote_Control.pdf implementing Intel vPro technology would • Virtualization. By using Intel VT-d and “Evaluating Intel® Anti-Theft Technology.” affect all parts of the enterprise and must Intel VT-x to support a mixed OS http://download.intel.com/it/pdf/Evaluating_ be carefully planned and implemented. First, environment, we have found that these Intel_Anti-Theft_Technology.pdf we standardized our computing platform systems perform up to 11 percent faster, and on desktop and laptop PCs equipped with “New Security Solutions Using Intel® vPro™ we can reduce hardware acquisition costs. Intel vPro processors. We also created an Technology.” http://download.intel.com/it/ • Remote management. One PoC implementation plan, defined a set of valuable pdf/New_Security_Solutions_Using_Intel_ demonstrated that Intel AMT can reduce use cases, and developed a set of best vPro_Technology.pdf

ACRONYMS DNS Domain Name System Intel® VT-x Intel® Virtualization Technology Intel® AMT Intel® Active Management Technology KVM Remote Control Keyboard-Video-Mouse Remote Control Intel® AT Intel® Anti-Theft Technology NIC network interface card Intel® TXT Intel® Trusted Execution Technology PKI public key infrastructure Intel® VT-d Intel® Virtualization Technology for PoC proof of concept Directed I/O ROI return on investment

For more information on Intel IT best practices, visit www.intel.com/it.

This paper is for informational purposes only. THIS DOCUMENT IS PROVIDED Intel, the Intel logo, Intel vPro, and Intel Core are trademarks of Intel “AS IS” WITH NO WARRANTIES WHATSOEVER, INCLUDING ANY Corporation in the U.S. and other countries. WARRANTY OF MERCHANTABILITY, NONINFRINGEMENT, FITNESS FOR * Other names and brands may be claimed as the property of others. ANY PARTICULAR PURPOSE, OR ANY WARRANTY OTHERWISE ARISING OUT OF ANY PROPOSAL, SPECIFICATION OR SAMPLE. Intel disclaims all Copyright © 2010 Intel Corporation. All rights reserved. liability, including liability for infringement of any proprietary rights, relating to use of information in this specification. No license, express or implied, by estoppel or Printed in USA Please Recycle otherwise, to any intellectual property rights is granted herein. 1010/JLG/KC/PDF 323954-001US