Security2 publishers2 min readPublished
Microsoft puts a Linux container runtime on Windows laptops with an Intune off switch
Microsoft made WSL Containers generally available with a wslc.exe CLI, an app-facing API, and Intune settings to disable it or allow-list registries. Through that API any native Windows app can start a Linux container, so policy has to cover software launches as well as developers at a prompt.
The Watch · Security desk

What happened
- The feature installs through a routine wsl --update or from Microsoft's GitHub releases page.
- Defender for Endpoint's existing WSL plugin now covers containers, surfacing process, file and network activity and tying it back to the Windows host.
- VS Code Dev Containers can use wslc as its default driver, and Aspire and the VS Code Containers extension already support WSL Containers.
- Compose support is the top feature request, and Microsoft says work on a wsl compose up command has started.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Intune administrators have to pick a state for WSL Containers: off, limited to approved registries, or open. Whatever they pick takes effect on machines as developers update WSL.
- constraint Container telemetry and policy, as Microsoft describes them, come through Defender for Endpoint and Intune, so shops running other endpoint products are outside what Microsoft has shipped.
- precedent Once wsl compose up ships, existing compose.yaml stacks are meant to run on the same laptops unchanged. More of a team's services would then fall under whatever container policy is set now.
For code already running on a Windows laptop, the API is the new capability. Microsoft's pitch is to "run Linux containers programmatically in your native Windows apps," for "running local AI workloads or using cloud-based containerized applications locally" [4].
The CLI builds images as well as running them. Microsoft describes wslc.exe as a way "to directly build, run and deploy Linux containers on Windows" [3]. Detection rules keyed on process names need two entries: wslc.exe and its built-in alias, container.exe [3].
The registry control is written around pulls. "With container registry allow lists, administrators can define approved registries and help ensure developers only pull container images from that list, that meet organizational security and compliance requirements," Microsoft said [9]. Neither report says how that policy treats an image built on the laptop itself [9].
For data-loss and egress rules, look at the general availability additions that move data across the host boundary. They are copying files in and out, mount support, network connect and disconnect commands, and configurable storage locations [5]. Help Net Security also reports a new network mode for container workflows, called consomme [14].
The speed figure has no bearing on the security decision. Microsoft claims up to 2x faster access to Windows files from Linux environments, and Help Net Security notes that the "up to" wording makes it a ceiling [13].
What to watch
- Microsoft documentation on whether WSL Containers are enabled by default on devices with no Intune policy applied.
- Endpoint vendors other than Microsoft announcing visibility into process, file and network activity inside WSL containers.
- Whether the registry allow list governs images that wsl compose up pulls from existing compose.yaml files when that command ships.