Must use the correct Intel FPT tool from Intel ME7 or 8 package (Ex. Bios 9HKT41A uses ME7):
Bios settings can show you, the ME version that the system uses, depends on models and bios UI. Its a Intel Q65 and can use both versions.
Tool runs from an ADMIN CMD window in Windows (Intel ME driver should be installed) or from USB Boot to DOS/UEFI environment.
The tool can only read/write depending on the access provided in FD, further guidance here:
[Guide] Unlock Intel Flash Descriptor Read/Write Access Permissions for SPI Servicing - Special Topics / Intel Management Engine - Win-Raid Forum (level1techs.com)
The ME_DIS jumper its the switch to provide this access, still OEM rules on the bios/fd will retain it.
We need a full backup or just the bios_region:
fpt.exe -d full_spi.bin or fpt -bios -bios_reg.bin
I do advise to work only in the bios_region, mod it and flash it again back with FPT
fpt.exe -bios -nvme_bios_region.bin
Do you understand the risks of getting a bricked system? Just to be sure that this is USER OWN RISK and choice only. If bricked only with a backup bios image (NOT Lenovo bios files, it wont work) and a CH341 programmer it can be recovered. Or OEM specific methods if avavaible.
Take it easy and read what is posted and linked, rush is the killer of all things…