← In the News

Microsoft Execution Containers reach general availability

Microsoft Execution Containers: Policy-driven containment for AI agents · Logan Iyer, Corporate Vice President, Windows Platform + Developer, Microsoft · Windows Developer Blog, October 7, 2026

Machine-readable Download Markdown

Microsoft says Microsoft Execution Containers (MXC) is now generally available. A developer declares the files and network destinations a workload needs in one JSON schema, and MXC enforces that policy outside the agent, so "the agent or generated code cannot grant itself additional access." The process container uses AppContainer on Windows, Seatbelt on macOS and Bubblewrap on Linux. A Windows-only session container, a Linux-in-WSL container, and an experimental MicroVM cover stronger isolation.

MXC has three modes. Enforcement blocks anything not granted. Learning blocks it and writes a JSON activity report. Permissive allows it and records it. Microsoft says the activity report is available only on Windows. Microsoft lists GitHub Copilot, OpenAI Codex and Replit among agents that already support MXC, and Claude Code among those that will. Those adoption claims come from Microsoft and have not been checked against the vendors.

Why it matters: Writing a least-privilege policy for an agent is hard without knowing what it touches. A Learning mode that records denied accesses gives a team a way to derive the policy from a real run, where supported, instead of guessing it.