What are Microsoft Execution Containers (MXC)? Windows' new sandbox for AI agents
Short answer
Microsoft Execution Containers (MXC) is a policy-driven sandbox, now generally available, that limits what an AI agent can access. Developers and IT declare which files, network destinations and UI an agent may use, and MXC enforces that boundary at runtime from outside the agent, so the agent can't grant itself more access.
What are Microsoft Execution Containers (MXC)?
MXC is the containment layer Microsoft is building into Windows for AI agents. Logan Iyer, Corporate Vice President of Windows Platform + Developer, announced it on the Windows Developer Blog on October 7, 2026, and it is generally available now.
Microsoft calls it "a policy-driven execution layer for untrusted code or dynamically generated workloads." You can wrap a small piece, like model-generated code, a plugin or a tool. Or you can wrap the whole agent.
Containment is one of three pillars Microsoft lists. The other two are identity, which tells an agent's activity apart from a person's, and manageability, which gives organizations tools to govern and monitor agents. MXC covers the first.
Why do AI agents need a sandbox?
Microsoft's blunt version: "An agent cannot be its own security authority."
Its example is a coding agent asked to update a website. The agent needs to read and write the repository, and it may need to read the production server config. It should not change that config. But an agent might decide that editing the server config is the fastest way to finish the job. That choice can look reasonable to the agent and still break the live site.
With MXC, the boundary is set by the developer or the organization and enforced separately from the agent. If the agent tries to modify something it wasn't granted, the container is designed to block it, whatever the model, generated code, plugin or tool decides.
Which AI agent sandbox levels does MXC offer?
Four backends, from light to heavy:
- Process container (Windows 11, macOS, Linux): lightweight containment for responsive workloads. It uses each platform's own sandbox: AppContainer on Windows, Seatbelt on macOS and Bubblewrap on Linux.
- Session container (Windows 11 only): runs the agent under a separate Windows account and session, with its own desktop, clipboard, UI and input. It suits long-running agents.
- WSL container (Windows 11 only): a Linux environment through WSL, for Linux-first toolchains.
- MicroVM (Windows 11 and Linux, experimental): hardware-enforced isolation for higher-risk workloads.
Developers write against one JSON configuration schema and a multi-language SDK. MXC maps the requested controls to whichever backend you pick on Windows, macOS or Linux. Windows 365 support is also generally available, so agents can run in Cloud PCs with the same model.
What can an MXC policy control?
A policy covers five areas: the containment type, the process (command, arguments, working directory, environment), the file system (what can be changed, read only, or not touched at all), the network (inbound, outbound and loopback), and the user interface (whether the agent can reach the desktop).
For the website example, a policy could allow read and write on the repo, allow tools like Git, block the user's Documents folder, block network connections and block the desktop. The policy sits outside the agent's control.
Organizations can stack their own rules on top. Microsoft says Intune policy for MXC process containers on Windows 11 is coming soon, so IT can set limits without the agent developer hard-coding them.
How do Learning and Permissive modes help write a policy?
Writing a least-privilege policy is hard when you don't know everything an agent touches. MXC has three modes for this:
- Enforcement: ungranted access is blocked. No activity report. This is for production.
- Learning: ungranted access is blocked and recorded in a JSON activity report.
- Permissive: ungranted access is allowed but recorded, so the task finishes while you collect evidence.
The activity report is a Windows-only feature of process containers. Permissive mode doesn't bypass other operating system or organizational restrictions.
What is the MXC SDK?
MXC is a library you build into your app, not a separate product you install. According to the MXC repository on GitHub, your app specifies the container type, the containment rules and the command to run. MXC validates the request, picks the backend and launches the workload.
The repo lists Rust, .NET and Node SDKs, plus a versioned JSON format for requests and policies. Microsoft also suggests a shortcut: use your favorite coding agent to integrate the SDK and draft a first policy, then review and test it.
Which AI agents support MXC?
Microsoft says GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio and Unsloth AI already support it. NVIDIA has integrated OpenShell into MXC.
Announced as coming: Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent by Nous Research, Manus, Perplexity, Raycast and Simular.
The identity piece is not here yet. Microsoft says Windows will "soon" let Microsoft Entra separate agent activity from user activity in Microsoft Agent 365. That would let security teams cut off a misbehaving agent without locking out the employee using it.
Key facts
- Announced October 7, 2026 on the Windows Developer Blog. Generally available.
- Four backends: process container, session container, WSL container and MicroVM (experimental).
- Process containers run on Windows 11, macOS and Linux. Session and WSL containers are Windows 11 only.
- Three modes: Enforcement, Learning and Permissive. Activity reports are Windows-only.
- Supported today: GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio, Unsloth AI.
- Coming soon: Intune policy for process containers, and Entra agent identity through Agent 365.
FAQ
Is MXC only for Windows?
No. Process containers work on Windows 11, macOS and Linux, and MicroVM is experimental on Windows 11 and Linux. Session containers and WSL containers are Windows 11 only.
How do you sandbox an AI agent on Windows with MXC?
You integrate the MXC SDK into the agent, declare the files, network access and UI it needs in a JSON policy, and pick a backend such as a process or session container. Learning or Permissive mode helps you find what the agent actually uses before you enforce the policy.
Does OpenClaw support Microsoft Execution Containers?
Yes. Microsoft lists OpenClaw alongside GitHub Copilot, OpenAI Codex, Replit, LM Studio and Unsloth AI as agents that already support MXC.
Does Claude Code support MXC?
Not yet. Microsoft lists Anthropic Claude Code among the agents that will be releasing MXC support.
Can an AI agent change its own MXC policy?
No. Microsoft says the policy stays outside the agent workload's control, so the agent or the code it generates can't grant itself more access.
Sources
Keep reading
Get AI news decoded weekly.
Decoded is a free weekly email from Era of Minds. The AI stories that actually matter, in plain English. Five minutes, no hype.
You're in. Check your inbox.
Confirm your email and your AI Starter Kit is on its way.
Free. Unsubscribe anytime. Subscribers get the AI Starter Kit (50 prompts). More about Decoded