https://virtualizationreview.com/articles/2020/01/13/configu...
Intel ME is its own can of worms and can only be fully disabled by modifying the firmware image, see tools like me_cleaner.
https://github.com/corna/me_cleaner