Microsoft turns agent sandboxing into an OS feature: Execution Containers go GA on Windows 11
Microsoft made Microsoft Execution Containers generally available on Windows 11 on October 7, turning agent sandboxing from a developer preview into a shipped OS feature. Agents get their own identity, their own sandbox, and their own audit trail — enforced by Windows, not by the app asking nicely.
Microsoft announced on October 7, 2026 that Microsoft Execution Containers (MXC) are now generally available on Windows 11. MXC is a policy-driven execution layer for untrusted code and dynamically generated workloads — in plain terms, an operating-system sandbox for AI agents. The timing matters: it arrived at the company's Windows and Surface event in San Francisco, alongside a broader push to move AI work across PCs and the cloud.
The pitch is narrow and specific. Today, an AI agent that reads files, runs tools and takes actions typically borrows the user's privileges — full authority, no questions asked. MXC replaces that with a managed boundary: developers and IT administrators declare the files and network destinations an agent may use, and Windows enforces that policy at runtime. The agent cannot grant itself additional access, regardless of what the model, its generated code, or its plugins decide to do.
Three pillars: containment, identity, manageability
Microsoft frames the release around three platform capabilities. Containment limits what an agent can access and do. Identity distinguishes an agent's activity from a person's. Manageability gives organizations the tools to govern access and monitor agent activity.
Containment ships first. Developers declare the resources a workload requires through a unified JSON configuration schema and a multi-language SDK, and MXC maps the requested controls to the containment backend that fits. The model is portable: the same policy works across Windows, macOS and Linux, with Microsoft handling the platform-specific mechanics underneath.
A ladder of isolation, from process to VM
MXC offers four backends, from lightweight to hardware-backed:
Process containers run on Windows 11, macOS and Linux, using the platform-appropriate sandbox — AppContainer on Windows, Seatbelt on macOS, Bubblewrap on Linux. They are the low-latency option for responsive work like model-generated code and tool execution. Session containers are Windows-only: the agent runs in a separate, OS-isolated session with its own local agent identity and isolated desktop, clipboard, UI and input boundaries. WSL containers (WSLc), also Windows-only, give Linux-first agent toolchains a Linux execution environment through WSL. MicroVMs, available on Windows 11 and Linux, are hardware-backed and still experimental — reserved for the highest-risk workloads.
Policy covers five areas: the containment environment itself, the process (command, arguments, working directory), the file system (what can be modified, read, or never touched), the network (inbound and outbound connectivity, including loopback), and the user interface (desktop and UI access). A policy for a coding agent, for example, might grant read and write access to the source repository and access to Git — while blocking the Documents folder and all network connections.
Three modes: enforce, learn, or just watch
Writing a least-privilege policy is hard when you don't yet know every resource a workload will touch. MXC answers with three operating modes. Enforcement blocks ungranted access for production. Learning blocks ungranted access and records each attempt in a JSON activity report, so developers can reproduce failures and see exactly which resources the workload tried to reach. Permissive records what the policy would have denied but lets the operation continue — useful while authoring the policy, since the workload can finish while evidence accumulates. Activity reports are a Windows-only feature.
Microsoft also supports the full lifecycle: agent developers declare the resources their workloads may need, and organizations can layer additional constraints through management policy — Intune policy for managing MXC process containers on Windows 11 is coming, so the same agent can run inside different enterprise boundaries without the developer encoding the company's security posture into the app.
Who's aboard — and what's still coming
The ecosystem list is unusually long for a GA announcement. Already supporting MXC: GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio and Unsloth AI. NVIDIA has integrated its OpenShell into MXC with policy controls for agent access to files and inference services, advanced network controls, credential management and OCSF auditing for enterprises. And Microsoft names the next wave: Anthropic Claude Code, Perplexity, Manus, Raycast, Box, Egnyte, Heidi Health, Simular — and Hermes Agent by Nous Research, whose $90 million Series B we covered earlier today.
What's not shipping yet: Microsoft Entra support to distinguish agent activity from user activity inside Agent 365 — so a compromised agent can be quarantined without blocking the employee's access — and the extension of Agent 365 controls to local on-device agents. Windows 365 support for MXC, though, is GA now, letting agents run on Cloud PCs with the right isolation model.
Why it matters
Enterprise AI adoption is gated on two questions IT keeps asking: what can this agent touch, and can we prove it? Microsoft is answering both at the OS layer — the same way process isolation and app containers once moved application security from "trust the developer" to "enforced by the platform." Agents are moving from chat boxes to tools that read files, run commands and act across systems; giving them capabilities without giving them the user's keys is the precondition for letting them work inside real enterprises. Microsoft just made the sandbox the operating system's job.
Sources: Windows Developer Blog (Oct. 7, 2026); Unite.AI (Oct. 7, 2026); WindowsReport (Oct. 7, 2026).