Microsoft Execution Containers (MXC ) are now generally available (GA), says Redmond. That’s a sandboxed code execution system for running untrusted code (model output, plugins, and tools) on Windows, Linux, and macOS. The idea in brief? A platform for managing AI agents on your computer that lets you decide which files, websites and programs an agent can touch, and Windows enforces those limits.
Microsoft first teased MXC at its Build conference in April 2026. The MIT-licensed code for MXC has been freely available for months. Redmond’s support across Windows 11 is now more mature, although not comprehensive. (More below.)
Microsoft describes MXC as the “containment layer” for agents, with Logan Iyer, its VP for Windows Platform + Developer writing this week that “Developers and IT administrators define the resources, like files and network destinations an agent can use and MXC uses the appropriate container to enforce those policies at runtime.”
It’s an SDK dependency, written in Rust, you add to your app. Users applications specify container type (there are four); containment rules; workload command
MXC validates the request and launches the workload in the chosen container.
Iyer said that currently “Only Windows supports a session container, which runs an agent on the user’s device in a separate, OS-isolated session with its own local agent identity and isolated desktop, clipboard, UI, and input boundaries…”
There are three container types and one MicroVM one users can specify; the latter ensuring “hardware-enforced isolation and full Linux workload compatibility.”
Not Intune-ready, yet
Organisations will be able to add “additional constraints” through the likes of Microsoft Intune management policy. That doesn’t seem to be ready yet, which may make some sceptical about just how enterprise-ready-GA this actually is. (“Intune policy will soon be available to manage MXC process containers used by MXC-integrated agents on Windows 11,” said Iyer, without sharing a firm timeline.)
Named agent platform integrations already available include GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio and Unsloth AI, Microsoft said, adding that Claude Code, Box, Manus and Perplexity are expected to follow.
For all the not-entire-finished nature of the release, technologists will welcome the progress. One CTO of a FTSE 100 company told The Stack last week “the challenge of running agents safely at scale,” was the biggest live issue for industry to solve.” He added: “Today, when we select an agent platform, we're selecting solutions for identity management, entitlements, containerization, runtime infrastructure, sandboxes, and of course observability and telemetry. [Each solution] has its own differences, its own potential gaps, which can make it quite hard to switch between platforms and between models and between providers, and if we solve this problem at scale, it will really help the industry as a whole to deliver better AI solutions.”