Pull to refresh
Logo
Microsoft makes execution containers for AI agents generally available

Microsoft makes execution containers for AI agents generally available

New Capabilities

New policy layer lets IT define which files and networks agents can access, enforced by the OS at runtime

Yesterday: MXC generally available on Windows 11

Overview

Updated 2 hours ago

A coding agent that reads the source repository but can't open the finance team's files, and a support bot that reaches the product database but not the public internet—Microsoft built that level of control into Windows 11 when Execution Containers (MXC) went generally available on October 7.

MXC is a policy engine for AI agents. Developers write a JSON policy declaring which files, network addresses, and processes a workload may use, and the agent runs inside a container that enforces those limits at runtime. The policy sits outside the agent's control, so generated code can't quietly grant itself more access.

OpenAI's Codex and GitHub Copilot already run inside MXC. Anthropic's Claude Code and eight other agents are scheduled to follow, and Microsoft says management through Intune and its Agent 365 service is coming. The payoff: organizations can delegate real work to autonomous agents without giving them the signed-in user's full authority.

Why it matters

MXC lets enterprises delegate sensitive work to AI agents without granting full user authority, removing a key obstacle to agent adoption at scale.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

137B
Parameters in MAI Code 1.1 Flash
Coding model running locally on PCs; 6.8 billion active parameters in 3-bit precision.
7
AI agents supporting MXC at launch
Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, OpenShell, and Unsloth AI.
4
Containment backends
Process, session, WSL, and experimental microVM isolation on Windows 11.
256K
Local context window
Tokens of context supported locally by MAI Code 1.1 Flash.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

2026 October 2026

3 events Latest: Yesterday
  1. MXC generally available on Windows 11

    Latest Product Release

    Containment layer for AI agents goes live with process, session, WSL, and experimental microVM backends; Windows 365 support also GA. Codex, GitHub Copilot, and five other agents added support.

  2. MAI Code 1.1 Flash and RTX Spark PCs announced

    Product Release

    Microsoft said MAI Code 1.1 Flash runs locally in 3-bit precision and opened pre-orders for Surface and NVIDIA RTX Spark systems.

  3. MXC and WSL 3 unveiled at Microsoft Build

    Announcement

    Microsoft previewed Execution Containers and the WSL 3 update for developers at its annual conference.

Scenarios

1

Intune management for MXC ships, cementing enterprise rollout

Likely Resolves by Q1 2027

Discussed by: Microsoft's Windows developer and experience blogs

Microsoft says Intune policy for MXC process containers will be available 'soon,' giving IT control over how Windows evaluates container creation requests and which boundaries get enforced. If that ships alongside Agent 365 local controls and Entra identity separation, MXC becomes the managed default for enterprise agents on Windows.

2

Claude Code and listed partners ship MXC support

Possible Resolves by End of 2027

Discussed by: Windows Experience Blog list of upcoming adopters

Nine agents were named as coming to MXC, led by Anthropic's Claude Code, with Box, Egnyte, Manus, Perplexity, and Raycast among the others. If even the marquee names ship production support, the containment layer gains cross-vendor traction rather than staying Microsoft-only.

3

Rivals launch competing agent containment standards

Uncertain Resolves by End of 2027

Discussed by: Industry observers tracking agent sandboxing

MXC's process backend works on macOS and Linux, but its flagship session, WSL, and microVM backends are Windows-only. If Apple or Google ships its own agent policy framework, the containment market fragments instead of consolidating on Microsoft's JSON schema.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

September 2008

Chrome's sandbox (2008)

Google launched Chrome with every tab, plugin, and renderer running inside a restricted OS sandbox, so a compromised web page couldn't read the rest of the machine.

Then

Chrome's isolation model set a new security baseline for browsers.

Now

Every major browser adopted sandboxing; it became the default way to run untrusted third-party code.

Why this matters now

MXC applies the same principle to AI-generated code: run untrusted workloads behind OS-enforced boundaries instead of trusting them.

July 2008

iOS App Sandbox (2008)

Apple required every third-party iPhone app to run in its own sandbox with declared entitlements describing what it could access.

Then

Developers declared capabilities up front and the OS enforced them.

Now

The pattern of declared permissions plus platform enforcement became standard in mobile and desktop OSes.

Why this matters now

MXC is a direct descendant: developers declare which resources an agent may use, and the OS enforces that boundary.

March 2013

Docker (2013)

Docker popularized OS-level containers, letting developers package and run applications in isolated user-space environments with a standard toolchain.

Then

Containerization became the default way to ship and scale cloud software.

Now

The tooling normalized the idea of isolating workloads, but left policy definition to operators.

Why this matters now

MXC reuses container isolation but adds a policy layer written for AI agents, declaring resource boundaries in JSON rather than packaging entire applications.

Sources

(7)