HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links★ Pro Subscribe free
← Back to Blog
Intune IntuneIntel vProHardwareOut-of-band ManagementDevice Management

Intel vPro Fleet Services in Intune: Managing a Device That Won’t Boot

IA
Imran Awan
3 October 2026
Start here — and a date worth being honest about

Intel vPro Fleet Services became available directly inside the Intune admin center on 15 October 2025 — this is not breaking news, and anyone telling you it just shipped in 2026 has the date wrong. What it is, though, is genuinely under-covered: a free capability most organisations already own the hardware for, sitting in a Partner portals tab almost nobody opens, that lets you power on, diagnose and recover a device even when the operating system won't boot or the device is switched off.

If your fleet runs Intel vPro-capable hardware (8th Gen Intel Core or newer) and you've never looked at the Partner portals tab in Intune, this post explains what's there, what it actually requires, and what it genuinely cannot do.

Intune manages what the operating system can see. The moment the OS can't boot, won't respond, or the device is simply switched off, Intune's visibility ends at exactly the point where you need it most. Intel vPro exists specifically to cover that gap, and Microsoft folded access to it directly into the Intune admin center a year ago. This post explains the mechanism, what it genuinely requires, and where the real limits are — because "manage a device that's turned off" sounds like marketing until you understand what's actually happening underneath it.

The short version

Intel vPro provides out-of-band management — hardware-level remote access built on Intel Active Management Technology (AMT), operating below and independently of the operating system. On supported hardware (8th Gen Intel Core processors and newer), it lets you remotely power a device on, run BIOS-level diagnostics, perform system recovery or re-imaging, and use keyboard-video-mouse (KVM) control — all without a functioning OS and without sending a technician. Intel vPro Fleet Services is Intel's cloud-hosted layer that activates AMT without the on-premises infrastructure historically required, and since October 2025 it's been reachable directly from Devices › Partner portals in the Intune admin center, authenticated through your existing Entra ID credentials, at no extra licensing cost. The one thing it is not: a software fix for a broken OS. It gets you to the device when nothing else can — what you do once you're there is still on you.

Who needs to read this

If you are…What this means for you
Desktop / field supportA device that won't boot no longer automatically means a truck roll or a shipped replacement, if the hardware qualifies and AMT has been activated.
Intune / endpoint engineerThis is a Partner portal, not a policy — there's nothing to configure in Intune itself beyond checking the tab exists and is provisioned.
Procurement / hardware refresh planningMany organisations already own vPro-capable devices without realising the remote-manageability features were never switched on. Check before assuming this needs a hardware purchase.
Security / complianceA powered-off or unreachable device isn't necessarily an unmanageable one any more — relevant to any conversation about devices that go dark for extended periods.

The problem: Intune's visibility ends exactly where you need it most

Intune, like every MDM platform, is fundamentally software managing software. It talks to an agent running inside Windows, which means its reach stops the instant Windows itself stops responding. A corrupted operating system, a failed patch that won't let the device boot, a BitLocker recovery loop, or simply a device that's switched off — in every one of these cases, Intune has nothing left to talk to.

The real-world consequence is familiar to anyone running field support at scale: a device goes dark, and the only options left are talking a non-technical user through recovery steps over the phone, shipping a replacement, or sending someone on site. For a remote worker, a field engineer, or a device on a factory floor, each of those options costs real time and money, and in the meantime the device sits unreachable — and, if it's unreachable, potentially unpatched and unmonitored too.

📋 Note: this isn't a flaw in Intune. It's a coverage gap any OS-level management tool has by definition. As Intel's Gina McFarland put it describing this exact limitation: "As long as the device is powered on, the OS is healthy and the network stack is functioning, it does exactly what it's supposed to do." The qualifier is the whole problem.

Why it happens: AMT has existed for years, but was never activated

The underlying capability here isn't new at all. Intel Active Management Technology (AMT) has shipped inside vPro-capable hardware for more than a decade, operating at the silicon level, independent of whatever operating system is installed. AMT is what makes it possible to reach a device's BIOS, power state, and basic hardware over the network, regardless of whether Windows is running, crashed, or absent entirely.

The gap was never the hardware — it was activation. Historically, turning AMT on required specialised expertise and on-premises infrastructure most organisations never built, so the capability sat dormant inside hardware bought for entirely different reasons (business-grade security and performance, not remote recovery). Many organisations today own AMT-capable fleets and have simply never switched the feature on.

Intel vPro Fleet Services is what changes that. It's a cloud-hosted service that activates AMT without requiring the on-premises servers and specialist setup that used to be the barrier — and since October 2025, Microsoft surfaces access to it directly inside the Intune admin center's Partner portals, rather than it being a separate product IT teams have to go find and onboard independently.

✅ Tip: Intune and vPro aren't competing tools, and framing them that way misses the point. Intune manages from the OS up — compliance, policy, app delivery. vPro manages from the hardware down — recovery when software tools can't connect at all. One does not replace the other; they cover different failure conditions entirely.

How to verify: does your hardware qualify, and is it already there?

  1. Check whether your fleet runs 8th Generation Intel Core processors or newer. This is the hardware floor for Intel vPro Fleet Services as surfaced through the Intune Partner portal.
  2. In the Microsoft Intune admin center, go to Devices › Partner portals and check whether Intel vPro® Fleet Services appears in the list alongside any other OEM portals you already use (Dell Management Portal, HP Connect Portal, Surface Management Portal).
  3. If it appears, selecting it authenticates using your existing Microsoft Entra tenant credentials and takes you directly to the Intel vPro Fleet Services management portal — there's no separate sign-in or account to create.
Intune Admin Center — Devices › Partner portals
Intel vPro® Fleet Services›
Dell Management Portal›
⚠ Gotcha: the portal being listed doesn't mean AMT is already activated on your devices. Activation is a separate step, and until it's done, the hardware capability exists but isn't reachable. Don't assume coverage just because the tile is visible — confirm devices show as managed inside the Fleet Services portal itself before relying on it during an actual incident.

The fix: finding it in the admin center, and what it actually requires

  1. Confirm hardware eligibility first (8th Gen Intel Core or newer) across the devices you want covered — this determines scope before anything else.
  2. In the Intune admin center, go to Devices › Partner portals and select Intel vPro® Fleet Services.
  3. Authenticate with your existing Entra ID credentials when prompted — this reuses your existing conditional access policies for hardware management operations, rather than introducing a separate identity model.
  4. Inside the Fleet Services portal, activate AMT for the devices you want covered. This is the step that actually turns the dormant hardware capability on; simply having the portal available does not activate anything by itself.
  5. Once activated, the out-of-band capabilities become available for that device: remote power-on, BIOS-level diagnostics, system recovery and re-imaging operations, and security compliance monitoring even while the device is offline.
⚠ Warning: activation at scale is where organisations most often fall short, according to Intel's own messaging on this — devices have to be activated correctly, configured securely, and managed consistently across the fleet, or the capability sits there unused exactly as it did before this integration existed. If you're rolling this out past a handful of pilot devices, plan activation as a deliberate project rather than something that happens by itself once the portal is visible.

Licensing-wise, this requires no additional fees or infrastructure beyond your existing Intune licensing — Microsoft's own wording is explicit that it's accessible "with existing Intune licensing." The cost, such as it is, is the effort of activating and standardising AMT across your fleet, not a new line item.

Proof it worked: recovering a device that would otherwise need a truck roll

The real test of this capability isn't a configuration screen — it's what happens the next time a device goes properly dark.

Intel vPro Fleet Services — device state
Device: LAPTOP-7Q2KX1
OS reachability (Intune): Unreachable — last check-in 3 days ago
Hardware reachability (vPro): Online — AMT active
Action taken: Remote power-on, BIOS diagnostic run, boot media attached for recovery — no technician dispatched
✅ Tip: the outcome worth measuring isn't "did the device come back online" — it's "did it come back online without anyone driving or shipping anything to reach it." That's the entire value proposition, and it's trivial to prove with a before/after count of truck rolls or replacement shipments once activation has been rolled out across a fleet.

Quick reference: capabilities, requirements, and limits

CapabilityWhat it does
Hardware-level accessManage a device even when powered off or the OS has crashed
Remote power-onPower a device on remotely for maintenance or updates
BIOS-level diagnosticsRun diagnostics and troubleshooting below the OS layer
System recovery / re-imagingRecover or re-image a device without an on-site visit
Offline compliance monitoringSecurity compliance visibility even while a device is offline
KVM (keyboard-video-mouse)Full remote screen/input control independent of OS state
RequirementValue
Hardware floor8th Generation Intel Core processors or newer, vPro-enabled
AuthenticationExisting Microsoft Entra ID credentials, reusing existing conditional access policies
LicensingNo additional fees or infrastructure — included with existing Intune licensing
Where it livesIntune admin center › Devices › Partner portals
ActivationA separate, deliberate step per device — not automatic just because the portal is visible
Available since15 October 2025 (Intune admin center integration)
📋 Note: this joins an existing family of OEM integrations in the same Partner portals tab — the Surface Management Portal, the HP Connect Portal (announced spring 2023), and the Dell Management Portal that arrived the year before Intel's. If you already use one of those, Intel vPro Fleet Services behaves the same way: authenticate once, land directly in the OEM's own management surface.

Glossary

TermWhat it means here
Out-of-band managementManaging a device through a channel that operates independently of its operating system and main network stack — so it keeps working even when the OS doesn't.
Intel AMT (Active Management Technology)The underlying silicon-level capability built into vPro hardware that makes out-of-band management possible. Has existed for years; the gap was always activation, not the hardware.
Intel vPro Fleet ServicesIntel's cloud-hosted service that activates AMT without requiring on-premises infrastructure, now reachable from inside the Intune admin center.
ActivationThe deliberate step that turns on the dormant AMT capability on a specific device. Owning vPro-capable hardware does not mean this has already happened.
Partner portalsThe Intune admin center tab (under Devices) that surfaces OEM-specific management portals — Dell, HP, Surface, and now Intel — behind a single Entra ID sign-in.

Frequently asked questions

Is this a new Intune feature?

The Intune admin center integration arrived on 15 October 2025, so it's been available for a year as of this writing — not new, but genuinely under-used, since most IT teams have never opened the Partner portals tab.

Do we need to buy new hardware for this?

Possibly not. Many organisations already own 8th Gen Intel Core or newer vPro-capable devices, purchased for general business-grade security and performance, without the remote-manageability features ever having been activated. Check your existing fleet's processor generation before assuming a refresh is needed.

Does this replace Intune?

No. Intune manages from the OS up — compliance, policy enforcement, application delivery. Intel vPro manages from the hardware down, for the specific case where the OS can't respond at all. They cover different failure conditions and are designed to be used together, not as alternatives.

Is there a cost beyond our existing Intune licence?

Microsoft's own description is explicit: no extra fees or infrastructure are required beyond existing Intune licensing. The real cost is the operational effort of activating and standardising AMT consistently across a fleet, which some organisations choose to get help with through a partner rather than doing entirely in-house.

Can vPro fix a corrupted operating system by itself?

No. It gets you to the device — power, BIOS, diagnostics, KVM, attaching recovery media — when nothing else can reach it at all. What you do once you have that access (reimage, repair, restore) is still a decision and an action an admin takes; vPro is the path in, not an automated fix.

References

Was this post helpful?
React below — no account needed
Share this post
LinkedIn X / Twitter Reddit Bluesky

More from EndpointWeekly

Intune
Autopilot-Capable Isn’t Autopilot-Registered: The Hardware Gap…
A laptop can meet every Windows Autopilot hardware requirement on paper and still fail…
Intune
Intune and Apple WWDC 2026 — What IT Admins Need to Know
Apple WWDC 2026 brought major changes to MDM management — new declarative device…
Intune
What's New in Microsoft Intune — June 2026
Microsoft Intune June 2026 release — new Autopilot device preparation updates, Copilot…