Microsoft Makes Windows a Safer Runtime for AI Agents
Microsoft has made Microsoft Execution Containers, or MXC, generally available on Windows 11. The technology gives developers and organizations a way to run AI agents inside policy-defined boundaries instead of allowing them unrestricted access to a user’s files, network, and applications.
The announcement matters as AI agents move beyond chat and begin browsing files, running code, using tools, and completing multi-step tasks. Those capabilities can improve productivity, but they also create a security problem: an agent may need access to a project repository or development tool without needing access to unrelated personal files or production systems.
What Microsoft Execution Containers do
MXC is a policy-driven execution layer for untrusted code and dynamically generated workloads. Developers declare the resources an agent needs, such as specific files and network destinations, and MXC enforces those limits at runtime. The policy remains outside the agent’s control, so the agent or its generated code cannot grant itself additional access.
Microsoft supports several containment options. Process containers are available on Windows 11, macOS, and Linux. Windows 11 also supports session containers for stronger desktop separation and WSL containers for Linux-focused toolchains. MicroVM support is experimental on Windows 11 and Linux.
Windows 365 support for MXC is generally available, allowing agents to run on Cloud PCs. Microsoft says its Windows integration also provides a path toward agent identity and management: Entra-based separation of agent and user activity, plus Intune policy controls for MXC process containers, are described as coming soon.
Microsoft says leading tools already support MXC, including OpenAI Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell, and Unsloth AI. Meta’s Muse for Windows is also planned as a native Windows application with MXC integration.
How developers can get started
- Review Microsoft’s Windows agent development resources and identify the files, commands, and network destinations the agent actually needs.
- Integrate the MXC SDK and configuration schema into the agent or its execution harness.
- Start with learning or permissive policy modes to observe access requirements, then move to enforcement after reviewing the activity.
- Test the agent with the smallest practical set of permissions and verify that blocked operations fail safely.
Why it matters
MXC does not make an AI agent trustworthy by itself. Organizations still need to review the agent’s tools, identities, secrets, data access, and policies. Its value is that the operating system can enforce a boundary independently of the model, prompt, plugin, or generated code.
That approach represents a significant change in application security. Instead of treating agents like ordinary desktop programs, Windows is giving them restricted workspaces and, over time, distinct identities and management controls. For businesses adopting autonomous software, those boundaries could make useful automation easier to deploy without granting every agent the full authority of the person who launched it.
References
- Iyer, L. (2026, October 7). Microsoft Execution Containers: Policy-driven containment for AI agents. Windows Developer Blog. https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-driven-containment-for-ai-agents/
- Davuluri, P. (2026, October 7). Building Windows for hybrid intelligence. Windows Experience Blog. https://blogs.windows.com/windowsexperience/2026/10/07/building-windows-for-hybrid-intelligence/
- Microsoft. (n.d.). Build and run agents locally on Windows. Microsoft Developer. https://developer.microsoft.com/en-us/windows/agentic
- Microsoft. (n.d.). Microsoft Execution Containers. GitHub. https://github.com/microsoft/mxc/tree/main
