Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished Updated

Microsoft makes Execution Containers generally available for OS-enforced agent permissions

Microsoft made Microsoft Execution Containers, its policy layer for limiting what AI agents can touch, generally available on Windows on October 7. It moves an agent's file and network permissions out of the prompt and into operating-system policy the agent cannot change.

The Engineer · Build desk

How we use AISend a correction

MXC backends vary by platform; microVMs experimental How the general availability of Microsoft Execution Containers reaches developers and Cloud PC users, by platform and backend.

MXC builds into an app as an SDK (Rust, .NET, Node). Developers choose session-container or process-sandbox isolation per workload. MicroVMs on Windows and Linux are experimental. macOS has only process containers. Windows 365 Cloud PC support is available; Entra separation is coming soon.

MXC backends vary by platform; microVMs experimental
WhoHowKindClaim
Application developersMXC builds into an application as an SDK dependency, with Rust, .NET and Node SDKs documented.capability15
Developers choosing a backendMust choose session-container or lightweight process-sandbox isolation by workload and the security properties they need.decision14
Teams wanting microVM isolationmicroVMs on Windows and Linux are marked experimental in Microsoft's launch materials.exposure7
macOS developersThe process container is the only backend Microsoft's launch materials list for macOS.constraint17
Cloud PC usersWindows 365 support is generally available for agents on Cloud PCs; Entra-based agent and user separation is coming soon.capability8

What happened

  • The October release extends one JSON policy model and set of SDKs across Windows, macOS and Linux, with a different operating-system mechanism enforcing the rules on each.
  • Backends differ by platform: process containers on all three systems, session and WSL containers on Windows only, and microVMs on Windows and Linux marked experimental.
  • The MXC source repository describes it as an SDK dependency that builds into an application, documenting Rust, .NET and Node SDKs.
  • Windows 365 support is generally available for agents on Cloud PCs, while Entra-based separation of agent and user activity and Agent 365 controls for local agents are listed as coming soon.
  • Microsoft named Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI as supporting MXC, without usage or deployment figures.

Why it matters

  • constraint Coverage depends on agent vendors building the SDK in, so an operator running a third-party agent gets the OS boundary only if that vendor has integrated MXC.
  • decision Security reviews now have to name a backend per workload, because the same JSON policy enforced by a process sandbox and by a separate Windows account protects different things.
  • exposure Teams that want microVM separation for production agents would be adopting a backend that both Microsoft's launch materials and its repository still label experimental.

In Microsoft's own example, a coding agent can write to its project repository and read deployment settings, and is blocked from changing those settings [5]. The rule lives in a policy that lists file paths and network destinations [3]. MXC picks a containment backend and enforces the policy at runtime, outside the agent's control [4]. A model told to leave deployment settings alone can still be talked out of it. According to RuntimeWire, Microsoft wants Windows to supply the boundary so developers no longer rely on instructions to the model or limits inside the agent application [11].

The boundary starts where the agent's application adopts it. The repository's description puts MXC inside the application build [15]. The operating system does the enforcing, but only for workloads an application launches through MXC [4][15]. In our view, a team running an agent from a product that has not integrated the SDK still depends on that product's own limits [15].

A shared policy format does not give every platform the same isolation [6][7]. On macOS, the process container is the only backend in the launch materials [17]. The Windows session container is the heavier option. It runs under a separate Windows account and isolates the agent's desktop, clipboard, user interface and input from the interactive user's session [13]. RuntimeWire describes that as a different level of separation from a lightweight process sandbox, and says developers must choose by workload and the security properties they need [14]. The same report also says MXC itself selects the backend [4]. The report leaves out how a developer overrides that selection.

Logan Iyer, Microsoft's corporate vice president for Windows Platform and Developer, announced general availability on the Windows Developer Blog [2]. It came 127 days after the SDK's early preview at Build on June 2, when Microsoft described it as a cross-platform layer for Windows and WSL [18][12]. The repository labels several backends experimental [16]. RuntimeWire says that means general availability does not cover every isolation option at the same maturity [16].

We think Microsoft put the boundary at the right layer. A permission the agent cannot edit has to sit below the agent, and a single policy format that three operating systems enforce through their own mechanisms is careful engineering [6].

What to watch

  • Whether Microsoft drops the experimental label from the microVM backend and the other backends its repository flags.
  • A ship date for Entra-based separation of agent and user activity and for Agent 365 controls over local agents.
  • Usage or deployment figures from Microsoft or from listed products such as Codex and GitHub Copilot.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption30
Hype gap+25
Incentives70
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Microsoft made Microsoft Execution Containers (MXC), its policy-driven system for restricting what AI agents and other untrusted workloads can access, generally available on Windows on October 7th.

    ReportedSupportedSource: RuntimeWire, citing the Windows Developer Blog2 sources— create a free account to open themView cited source
  2. [2]

    Logan Iyer, Microsoft's corporate vice president for Windows Platform and Developer, announced the release in a Windows Developer Blog post.

  3. [3]

    Developers define which resources a workload may use, including file paths and network destinations.

    ReportedSupportedSource: RuntimeWire, describing Microsoft's announcement2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. blogs.windows.com

    1 article · October 9, 2026

    Building Windows for hybrid intelligence (17 minute read)
  2. runtimewire.com

    1 article · October 10, 2026

    Microsoft makes its agent containment layer generally available on Windows

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories