So I have a 3-node cluster of optiplex 5060 micros with i5-6800. I have AMT enabled on a different VLAN from the hypervisor I have running and it works great for remote management. One thing to keep in mind that for the KVM access to continue to work, I had to add an HDMI dummy plugs to keep the display working after reboots. All of the other functions associated with AMT worked after reboots.
For your other questions: ATM would only be accessible from the network you have it running on without any firewall rules/port forwarding/NAT
Yes reset it to factory. Turn ATM off and reset it.
I use MeshCentral running on Debian on a small VM and then I access MeshCentral through the Web UI. If you have any Raspberry Pi’s laying around that aren’t being used, it would be a great candidate for that type of setup.