Microsoft Execution Containers GA: sandbox your AI agents
Microsoft Execution Containers (MXC) is GA on Windows 11. Agents get a file and network policy they cannot change. Check which of your agents support it.
Most small teams run coding agents with the same access as the person at the keyboard. Every file, every saved login, the whole network. Today Microsoft made the alternative official: Microsoft Execution Containers (MXC) is generally available on Windows 11. An agent declares what it needs, the OS enforces the boundary, and the agent cannot widen it. We covered the preview in August. Now it ships.
What actually happened
At its San Francisco event with NVIDIA on October 7, Microsoft announced MXC general availability next to new RTX Spark PCs. TechCrunch reports Satya Nadella said the feature will reach all Windows 11 users and works for any developer's agent, not only Microsoft's.
The Windows Developer Blog has the details:
- Four containment types. Process containers run on Windows 11, macOS, and Linux (AppContainer, Seatbelt, and Bubblewrap under the hood). Session containers give an agent its own Windows account, desktop, clipboard, and input; they are Windows 11 only. There are also WSL containers and experimental MicroVMs.
- Policy lives outside the agent. Developers define file system, network, process, and UI rules in a JSON schema through the MXC SDK. Microsoft says the policy "remains outside the agent workload's control." Generated code cannot grant itself more access.
- Supported now: OpenAI Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, and Unsloth AI. NVIDIA integrated OpenShell.
- Coming: Anthropic Claude Code, Box, Egnyte, Manus, Perplexity, Raycast, and others.
- Not here yet: Intune management of process containers and Entra separation of agent activity from user activity are both "soon."
The SDK, schema, and samples are on GitHub.
Why it matters for your business
An agent with your access is a liability. A coding agent that reads a poisoned README or a malicious package can do anything you can do. A container that allows only the project folder and three domains limits the damage to that folder.
Make it a buying question. Before your team adopts an agent tool, ask if it supports MXC. Six major agents already do. A vendor with no plan to support it is telling you something.
Do not wait for Intune. The fleet-wide controls are not ready. On a five-person team, you can still pick tools that support MXC now and keep agents off the machines that hold payroll and banking logins.
If you build agents, write the policy now. If your internal tools or client agents run on Windows, define the folders and endpoints they actually need. That list is useful documentation even before you enforce it.
Key takeaways
- Microsoft Execution Containers is generally available on Windows 11 as of October 7, 2026
- Agents run under a file, network, and UI policy they cannot change themselves
- Process containers also run on macOS and Linux; session containers are Windows 11 only
- Codex, GitHub Copilot, Replit, and others support it now; Claude Code support is announced
- Intune and Entra controls are still "soon," so small teams should choose supported tools now
Running agents with full access to the machine that holds your bank login? We build agent workflows with least-privilege access from day one: scoped folders, allowlisted endpoints, and logs you can read. See what we build, or tell us which agents your team runs today.
Sources: Windows Developer Blog, TechCrunch.
- #microsoft-execution-containers
- #windows-11
- #ai-agents
- #sandboxing
- #agent-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
New Relic AI Evaluation: score the transaction, not the call
New Relic AI Evaluation hits public preview in November with guardrail checks, RAG scoring, and cost-to-quality views. Build your golden dataset first.
Read itGitHub stacked pull requests GA: review AI code in small pieces
GitHub stacked pull requests are now GA on all plans, with the gh stack CLI and merge queue support. Why small PRs matter more when agents write code.
Read it