BuildNot yet confirmed elsewhere1 publisher2 min readPublished Updated
Microsoft makes Execution Containers generally available for OS-enforced agent permissions
Microsoft made Microsoft Execution Containers, its policy layer for limiting what AI agents can touch, generally available on Windows on October 7. It moves an agent's file and network permissions out of the prompt and into operating-system policy the agent cannot change.
The Engineer · Build desk
MXC builds into an app as an SDK (Rust, .NET, Node). Developers choose session-container or process-sandbox isolation per workload. MicroVMs on Windows and Linux are experimental. macOS has only process containers. Windows 365 Cloud PC support is available; Entra separation is coming soon.
- capability Application developers MXC builds into an application as an SDK dependency, with Rust, .NET and Node SDKs documented., claim 15
- decision Developers choosing a backend Must choose session-container or lightweight process-sandbox isolation by workload and the security properties they need., claim 14
- exposure Teams wanting microVM isolation microVMs on Windows and Linux are marked experimental in Microsoft's launch materials., claim 7
- constraint macOS developers The process container is the only backend Microsoft's launch materials list for macOS., claim 17
- capability Cloud PC users Windows 365 support is generally available for agents on Cloud PCs; Entra-based agent and user separation is coming soon., claim 8
| Who | How | Kind | Claim |
|---|---|---|---|
| Application developers | MXC builds into an application as an SDK dependency, with Rust, .NET and Node SDKs documented. | capability | 15 |
| Developers choosing a backend | Must choose session-container or lightweight process-sandbox isolation by workload and the security properties they need. | decision | 14 |
| Teams wanting microVM isolation | microVMs on Windows and Linux are marked experimental in Microsoft's launch materials. | exposure | 7 |
| macOS developers | The process container is the only backend Microsoft's launch materials list for macOS. | constraint | 17 |
| Cloud PC users | Windows 365 support is generally available for agents on Cloud PCs; Entra-based agent and user separation is coming soon. | capability | 8 |
What happened
- The October release extends one JSON policy model and set of SDKs across Windows, macOS and Linux, with a different operating-system mechanism enforcing the rules on each.
- Backends differ by platform: process containers on all three systems, session and WSL containers on Windows only, and microVMs on Windows and Linux marked experimental.
- The MXC source repository describes it as an SDK dependency that builds into an application, documenting Rust, .NET and Node SDKs.
- Windows 365 support is generally available for agents on Cloud PCs, while Entra-based separation of agent and user activity and Agent 365 controls for local agents are listed as coming soon.
- Microsoft named Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI as supporting MXC, without usage or deployment figures.
Why it matters
- constraint Coverage depends on agent vendors building the SDK in, so an operator running a third-party agent gets the OS boundary only if that vendor has integrated MXC.
- decision Security reviews now have to name a backend per workload, because the same JSON policy enforced by a process sandbox and by a separate Windows account protects different things.
- exposure Teams that want microVM separation for production agents would be adopting a backend that both Microsoft's launch materials and its repository still label experimental.
In Microsoft's own example, a coding agent can write to its project repository and read deployment settings, and is blocked from changing those settings [5]. The rule lives in a policy that lists file paths and network destinations [3]. MXC picks a containment backend and enforces the policy at runtime, outside the agent's control [4]. A model told to leave deployment settings alone can still be talked out of it. According to RuntimeWire, Microsoft wants Windows to supply the boundary so developers no longer rely on instructions to the model or limits inside the agent application [11].
The boundary starts where the agent's application adopts it. The repository's description puts MXC inside the application build [15]. The operating system does the enforcing, but only for workloads an application launches through MXC [4][15]. In our view, a team running an agent from a product that has not integrated the SDK still depends on that product's own limits [15].
A shared policy format does not give every platform the same isolation [6][7]. On macOS, the process container is the only backend in the launch materials [17]. The Windows session container is the heavier option. It runs under a separate Windows account and isolates the agent's desktop, clipboard, user interface and input from the interactive user's session [13]. RuntimeWire describes that as a different level of separation from a lightweight process sandbox, and says developers must choose by workload and the security properties they need [14]. The same report also says MXC itself selects the backend [4]. The report leaves out how a developer overrides that selection.
Logan Iyer, Microsoft's corporate vice president for Windows Platform and Developer, announced general availability on the Windows Developer Blog [2]. It came 127 days after the SDK's early preview at Build on June 2, when Microsoft described it as a cross-platform layer for Windows and WSL [18][12]. The repository labels several backends experimental [16]. RuntimeWire says that means general availability does not cover every isolation option at the same maturity [16].
We think Microsoft put the boundary at the right layer. A permission the agent cannot edit has to sit below the agent, and a single policy format that three operating systems enforce through their own mechanisms is careful engineering [6].
What to watch
- Whether Microsoft drops the experimental label from the microVM backend and the other backends its repository flags.
- A ship date for Entra-based separation of agent and user activity and for Agent 365 controls over local agents.
- Usage or deployment figures from Microsoft or from listed products such as Codex and GitHub Copilot.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption30
- Hype gap+25
- Incentives70
- Confidence62
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft made Microsoft Execution Containers (MXC), its policy-driven system for restricting what AI agents and other untrusted workloads can access, generally available on Windows on October 7th.
ReportedSupportedSource: RuntimeWire, citing the Windows Developer Blog2 sources— create a free account to open themView cited source - [2]
Logan Iyer, Microsoft's corporate vice president for Windows Platform and Developer, announced the release in a Windows Developer Blog post.
- [3]
Developers define which resources a workload may use, including file paths and network destinations.
ReportedSupportedSource: RuntimeWire, describing Microsoft's announcement2 sources— create a free account to open themView cited source - [4]
MXC selects a containment backend and enforces the policy at runtime, outside the agent's control.
ReportedSupportedSource: RuntimeWire, describing Microsoft's announcement2 sources— create a free account to open themView cited source - [5]
In Microsoft's example, a coding agent could write to a project repository and read deployment settings while being blocked from changing those settings.
ReportedSupportedSource: Microsoft example, as reported by RuntimeWire2 sources— create a free account to open themView cited source - [6]
Microsoft says developers can use a shared JSON policy model and SDKs across Windows, macOS and Linux, with different operating-system mechanisms enforcing the rules.
ReportedSupportedSource: Microsoft, as reported by RuntimeWire2 sources— create a free account to open themView cited source - [7]
Microsoft's launch materials describe process containers for Windows, macOS and Linux; Windows-only session containers and WSL containers; and microVMs on Windows and Linux marked experimental.
ReportedSupportedSource: Microsoft launch materials, as reported by RuntimeWire2 sources— create a free account to open themView cited source - [8]
Windows 365 support for MXC is generally available, allowing agents to run on Cloud PCs alongside users' existing work; Entra-based separation of agent and user activity and extensions to Agent 365 controls for local agents are described as coming soon.
ReportedSupportedSource: Microsoft October announcement, as reported by RuntimeWire2 sources— create a free account to open themView cited source - [9]
In a separate October 7th Windows platform announcement, Microsoft listed Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI among products that support MXC.
ReportedSupportedSource: Microsoft, as reported by RuntimeWire2 sources— create a free account to open themView cited source - [10]
Microsoft's announcement does not quantify usage or customer deployments of MXC.
- [11]
Microsoft wants Windows to supply the operating-system boundary around agents, rather than leave developers to rely on instructions given to the model or limits inside an agent application.
ReportedSupportedSource: RuntimeWire characterization of Microsoft's aim2 sources— create a free account to open themView cited source - [12]
At Build on June 2nd, Microsoft introduced the MXC SDK in early preview, initially describing a cross-platform execution layer for Windows and Windows Subsystem for Linux.
- [13]
Session containers run under a separate Windows account and isolate an agent's desktop, clipboard, user interface and input from the interactive user's session.
- [14]
Session-container isolation is a different level of separation from a lightweight process sandbox, and developers must choose according to the workload and the security properties they need.
- [15]
The MXC source repository describes MXC as an SDK dependency that builds into an application and documents Rust, .NET and Node SDKs.
- [16]
The MXC repository labels several backends experimental, which RuntimeWire says reinforces that general availability for MXC does not mean every isolation option has the same maturity.
- [17]
On macOS, the only backend listed in Microsoft's launch materials is the process container.
- [18]
MXC went from early preview at Build on June 2 to general availability on October 7 in 127 days, about four months.
Sources
1 independent publisher whose own reporting we read for this story.
- Building Windows for hybrid intelligence (17 minute read)
blogs.windows.com
1 article · October 9, 2026
- runtimewire.comMicrosoft makes its agent containment layer generally available on Windows
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Enterprise device managementFollow
- Operating system securityFollow
- AI Agent SandboxingFollow
Entities
- Windows Subsystem for LinuxFollow
- MicrosoftFollow
- Microsoft Execution Containers (MXC) SDKFollow
- Logan IyerFollow
- Microsoft EntraFollow
- Windows 365Follow
- Microsoft Agent 365Follow
- CodexFollow
- GitHub CopilotFollow