Package
com.samsung.klmsagent
KLMS Agent
Guidance
The "KLMS Agent" (Knox License Management Service) is a background component of Samsung's Knox platform, made by Samsung. When an app or EMM activates a Knox licence, the KLMS Agent on the device contacts Samsung's Knox licence server to authenticate the licence and unlock the Knox APIs and security features it grants. Many EMM integrations that manage Samsung devices rely on a Knox Platform for Enterprise (KPE) licence, and this agent is what activates it on the device. In an Android Enterprise, EMM or kiosk context this is Knox plumbing rather than bloatware. If your management relies on Knox features, disabling it can break Knox licence activation and the policies that depend on it, so treat it as caution and test before touching it on managed devices. It has no launcher icon and is not user-facing. Version note: Samsung's Knox licence model has changed over time. The old Enterprise License Manager (ELM) was replaced by the Knox Standard licence and has reached end of service, while legacy Knox License Manager (KLM) and ISV keys still work. The KLMS Agent remains the on-device licence activation component across these changes, and Knox SDK licence keys are still required as of this verification date.
Package intelligence
Observed signing, permission, version and size signals from contributing devices - descriptive of that sample, not a verdict. These come from the v2 Package Search sync, which not every device has contributed to yet, so for some packages this detail is partial or not present at all.
- Signed by the device maker's own signing key (Samsung), so it is an OEM preinstall, but 2 different certificates appear across the fleet, so OEMs ship their own builds of it. It also signs the Android framework, so it is a platform-level key on its device(s). Inferred from the certificate appearing only on Samsung devices (493 packages, 7791 observations).
- Its largest observed manifest declares 29 permissions: 9 signature or system-level, 6 install-time and 14 vendor or uncatalogued.
- Never reported as user-facing, so it runs as a background or system component rather than an app the user opens.
Declared permissions (29)
Largest permission set observed for this package. Text is Android's own published description where one exists; platform permissions Android does not document show their granted protection level (in grey) instead; vendor or unknown constants show the name only.
| Permission | Description |
|---|---|
ACCESS_LOCAL_NETWORK |
- |
ACCESS_NETWORK_STATE |
Allows the app to view information about network connections such as which networks exist and are connected. |
ACCESS_WIFI_STATE |
Allows the app to view information about Wi-Fi networking, such as whether Wi-Fi is enabled and name of connected Wi-Fi devices. |
BROADCAST_PACKAGE_REMOVED |
Signature-level system permission, for platform-signed apps. |
INTERACT_ACROSS_USERS |
Signature or privileged system permission. |
INTERACT_ACROSS_USERS_FULL |
Signature-level system permission, for platform-signed apps. |
INTERNET |
Allows the app to create network sockets and use custom network protocols. The browser and other applications provide means to send data to the internet, so this permission is not required to send data to the internet. |
MANAGE_DEVICE_ADMINS |
Signature-level system permission, for platform-signed apps. |
MANAGE_USERS |
Signature or privileged system permission. |
QUERY_ALL_PACKAGES |
Allows an app to see all installed packages. |
READ_PRIVILEGED_PHONE_STATE |
Signature or privileged system permission. docs ↗ |
RECEIVE_BOOT_COMPLETED |
Allows the app to have itself started as soon as the system has finished booting. This can make it take longer to start the phone and allow the app to slow down the overall phone by always running. |
START_ACTIVITIES_FROM_BACKGROUND |
Signature or privileged system permission. docs ↗ |
WAKE_LOCK |
Allows the app to prevent the phone from going to sleep. |
WRITE_SECURE_SETTINGS |
Signature or privileged system permission. |
WRITE_SETTINGS |
Allows the app to modify the system's settings data. Malicious apps may corrupt your system's configuration. |
com.samsung.android.knox.permission.KNOX_CONTAINER |
- |
com.samsung.android.knox.permission.KNOX_ENTERPRISE_DEVICE_ADMIN |
- |
com.samsung.android.knox.permission.KNOX_INTERNAL_EXCEPTION |
- |
com.samsung.android.knox.permission.KNOX_LICENSE_INTERNAL |
- |
com.samsung.android.knox.permission.KNOX_LICENSE_LOG |
- |
com.samsung.android.knox.permission.KNOX_PROXY_ADMIN_INTERNAL |
- |
com.samsung.android.knox.ppclient.permission.KNOX_PRIVACY_POLICY |
- |
com.samsung.android.security.permission.SAMSUNG_KEYSTORE_PERMISSION |
- |
com.samsung.klmsagent.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION |
- |
com.sec.enterprise.knox.permission.MDM_ENTERPRISE_TIMA_NOTIFICATION |
- |
com.sec.enterprise.permission.MDM_PROXY_ADMIN_INTERNAL |
- |
com.sec.knox.containeragent.USE_KNOX_UI |
- |
com.sec.knox.permission.KLMS_AGENT |
- |
Manage on devices
ADB commands for this package (the inverse of each is included so you can undo). Run from an authorised shell or wire the equivalent into your DPC. Verify on a test device first - this database doesn’t yet classify which packages are safe to change. --user 0 targets the current user; drop it (and use a privileged shell) to act device-wide.
/system, so Restore re-adds it (-k keeps app data)Seen on
Each record is a device profile (make + model + Android version). Each unique handset that syncs against a matching profile will increase the observations of a package, thereby increasing confidence that a package is expected to be on a device.
| OEM | Model | Android | Provenance | Observations | Last seen |
|---|---|---|---|---|---|
| Samsung | SM-A125F | Android 12 | OEM Samsung | 1 | 21 Jan 2026 |
| Samsung | SM-A135F | Android 14 | OEM Samsung | 3 | 21 Jan 2026 |
| Samsung | SM-A137F | Android 14 | - | 1 | 17 Jan 2026 |
| Samsung | SM-A236B | Android 14 | OEM Samsung | 2 | 10 Apr 2026 |
| Samsung | SM-A266B | Android 15 | - | 2 | 21 Aug 2025 |
| Samsung | SM-A266B | Android 16 | - | 1 | 26 Jan 2026 |
| Samsung | SM-A346B | Android 15 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-A515F | Android 13 | - | 1 | 30 Jun 2025 |
| Samsung | SM-A528B | Android 13 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A536B | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-A556B | Android 15 | - | 1 | 1 Jul 2025 |
| Samsung | SM-A566B | Android 16 | - | 2 | 4 Nov 2025 |
| Samsung | SM-F721B | Android 15 | - | 1 | 9 Jul 2025 |
| Samsung | SM-F766B | Android 16 | - | 1 | 11 Nov 2025 |
| Samsung | SM-G766B | Android 15 | - | 1 | 17 Oct 2025 |
| Samsung | SM-G780F | Android 13 | OEM Samsung | 1 | 29 Dec 2025 |
| Samsung | SM-G973U | Android 12 | OEM Samsung | 2 | 10 Jun 2026 |
| Samsung | SM-G991B | Android 15 | OEM Samsung | 1 | 19 Apr 2026 |
| Samsung | SM-M315F | Android 12 | - | 1 | 2 Feb 2026 |
| Samsung | SM-N950U1 | Android 9.0 | - | 1 | 20 Aug 2025 |
| Samsung | SM-N986B | Android 13 | - | 9 | 17 Jul 2025 |
| Samsung | SM-S721U | Android 15 | - | 5 | 5 Aug 2025 |
| Samsung | SM-S906B | Android 15 | - | 1 | 2 Jun 2025 |
| Samsung | SM-S908U | Android 16 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-S921B | Android 15 | OEM Samsung | 2 | 22 Jul 2025 |
| Samsung | SM-S921B | Android 16 | OEM Samsung | 1 | 27 Jul 2026 |
| Samsung | SM-S921U | Android 15 | - | 1 | 19 Jun 2025 |
| Samsung | SM-S926B | Android 16 | OEM Samsung | 1 | 14 Apr 2026 |
| Samsung | SM-S928B | Android 16 | OEM Samsung | 2 | 12 Jun 2026 |
| Samsung | SM-S928U1 | Android 15 | - | 1 | 12 Sep 2025 |
| Samsung | SM-S931B | Android 15 | - | 1 | 20 Sep 2025 |
| Samsung | SM-S931B | Android 16 | - | 1 | 23 Nov 2025 |
| Samsung | SM-S936B | Android 16 | - | 1 | 18 Dec 2025 |
| Samsung | SM-S937B | Android 15 | - | 1 | 25 Aug 2025 |
| Samsung | SM-S938B | Android 15 | - | 2 | 25 Aug 2025 |
| Samsung | SM-S942B | Android 17 | OEM Samsung | 1 | 25 May 2026 |
| Samsung | SM-T636B | Android 15 | - | 2 | 12 Oct 2025 |
| Samsung | SM-T976B | Android 13 | - | 1 | 21 Jul 2025 |
| Samsung | SM-X200 | Android 14 | - | 1 | 27 Aug 2025 |
| Samsung | SM-X716B | Android 15 | - | 1 | 27 Jun 2025 |
| Samsung | SM-X910 | Android 14 | - | 1 | 26 Jun 2025 |
| Samsung | SM-X910 | Android 15 | - | 1 | 12 Sep 2025 |
Known labels
Locale-aware display names seen in the wild.
| Label | Locale | Seen |
|---|---|---|
| KLMS Agent | en-gb | 22 |
| KLMS Agent | en-us | 16 |
| KLMS Agent | en | 13 |
| KLMS Agent | nl-nl | 5 |
| KLMS Agent | it-IT | 5 |
| KLMS Agent | en-nl | 3 |
| KLMS Agent | es-us | 3 |
| KLMS Agent | de-de | 3 |
| KLMS Agent | 2 | |
| KLMS Agent | en-GB | 2 |
| KLMS Agent | es-ES | 2 |
| KLMS Agent | es-es | 2 |
| KLMS Agent | fr-fr | 2 |
| KLMS Agent | it-it | 2 |
| KLMS Agent | fr-dz | 1 |
| KLMS Agent | pl-pl | 1 |
| KLMS Agent | en-au | 1 |
| KLMS Agent | ru-ru | 1 |
| KLMS Agent | en-US | 1 |
| KLMS Agent | pl-PL | 1 |
| KLMS Agent | es-US | 1 |
| KLMS Agent | fr-FR | 1 |