If clients receive IP configuration from a DHCP server and you can edit the configuration of the DHCP server, you can set DHCP Option 15 to the appropriate DNS suffix (i.e. server FQDN) and the AMT clients will pull it automatically. Then, if you never set an MEBx password on the client (different from AMT password), you need to set one now. However, if the error is "Invalid domain certificate, hash does not exists in list of trusted root certificates on AMT" , then it means there is no hash corresponding to the root CA certificate in the client's AMT, go over the Enroll custom CA certificate hash section and double check the SHA256 hash matches.