Spent hours trying to find this in the BIOS, then a search found this:
For ASRock Z890 motherboards on Ubuntu, the Intel MEI (Management Engine Interface) is typically unlocked or hidden by default in standard BIOS images, as many ASRock boards do not expose the MEBx (Management Engine BIOS Extension) configuration utility in the UEFI setup.
You are completely right about opening a ticket with ASRock :))
This āManufacturing Modeā is left open in the factory to write MAC addresses and Intel ME settings. Before sending the board to stores, the factory script must lock it, but ASRock often forgets to lock it in their BIOS.
You will not find any button for this in BIOS settings because it is not a user option. fwupd fails HSI-1 test because unlocked ME is a real security risk. Only ASRock support can fix this by releasing a new BIOS or ME tool with the lock enabledā¦