Back to News
SecurityAI Understanding briefing

Microsoft makes Execution Containers generally available for AI agents

Microsoft has declared Microsoft Execution Containers (MXC) generally available, providing a policy-driven containment layer to restrict AI agent access to files and networks on Windows, macOS, and Linux.

5 min readRead the linked source
Source-page capture accompanying Microsoft makes Execution Containers generally available for AI agents
Source referenceSource recorded
Publisher
blogs.windows.com
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Key terms

AI Agent
A software system that can observe, reason, and take actions to achieve a goal, often using tools and memory.
Feature
An input variable used by a model to make predictions.
Latency
The time between sending a request and receiving the model's output.
Test yourselfAI Agents Quiz

What happened

Microsoft announced that Microsoft Execution Containers (MXC) is now generally available as a platform capability for securing AI agents. MXC enforces policy-driven boundaries on agent workloads, preventing them from accessing resources beyond defined limits. The system supports multiple containment backends, including a Windows-specific session container, and integrates with Microsoft Entra for agent-level identity and Microsoft Agent 365 for management. NVIDIA has integrated OpenShell into MXC, and support is available for major agent frameworks like GitHub Copilot and OpenAI Codex.

Microsoft has made Microsoft Execution Containers (MXC) generally available, introducing a policy-driven execution layer designed to contain untrusted code and dynamically generated workloads, particularly AI agents. The system allows developers and IT administrators to define specific resources, such as files and network destinations, that an agent can access. MXC enforces these policies at runtime using appropriate container backends, ensuring that agents cannot grant themselves additional access or exceed their intended authority.

The platform supports a spectrum of containment options to suit different workload needs. On Windows, MXC offers a unique session container that runs agents in a separate, OS-isolated session with its own identity and isolated desktop, clipboard, and input boundaries. This allows for low- local execution while maintaining strict security boundaries. MXC also supports cross-platform deployment, mapping requested controls to backends on Windows, macOS, and Linux, and is available on Windows 365 Cloud PCs for cloud-based agent execution.

To aid in policy creation, MXC provides three operational modes: Enforcement, Learning, and Permissive. Enforcement mode strictly applies the policy, blocking unauthorized operations. Learning mode blocks unauthorized operations but records them in a JSON activity report to help developers understand resource usage. Permissive mode allows operations that would otherwise be denied while recording them, which is useful for initial policy authoring. This approach helps organizations craft least-privilege policies by identifying exactly which resources an agent attempts to use.

Microsoft is integrating MXC with its broader identity and management ecosystem. While not yet fully available, Windows will soon enable Microsoft Entra to distinguish agent activity from user activity within Microsoft Agent 365. This separation allows security teams to evaluate and manage agent behavior independently of the user, ensuring that a compromised or misbehaving agent does not disrupt the user's access to protected resources. Additionally, Intune management policies will soon be available to manage MXC process containers on Windows 11, allowing IT administrators to enforce organizational security postures.

Source details: blogs.windows.com ↗

Why it matters

This release addresses a critical security gap in agentic AI, where autonomous tools often require broad system access to function, creating significant risk. By decoupling agent permissions from user privileges, MXC allows organizations to deploy agents without granting them full user-level authority. This enables safer delegation of tasks, such as coding or data processing, while maintaining strict control over file and network access. The general availability marks a shift from experimental sandboxing to a standardized, OS-level security for enterprise and developer use.

The general availability of MXC represents a significant step in securing the deployment of AI agents in enterprise environments. As agents become more capable of executing complex tasks across files and networks, the risk of unintended or malicious actions increases. MXC provides a standardized, OS-level mechanism to mitigate these risks by enforcing strict boundaries on agent capabilities, thereby allowing organizations to leverage the productivity benefits of AI without compromising security.

By separating agent identity from user identity, MXC enables more granular security controls and better incident response. If an agent is compromised, security controls can target the agent's specific access without affecting the user's productivity. This is crucial for organizations deploying multiple agents, as it prevents a single misbehaving agent from causing widespread disruption or data loss.

The integration of MXC with existing tools like Microsoft Entra, Agent 365, and Intune simplifies the management of agent security for IT teams. This reduces the burden on developers to encode security policies into their applications, allowing them to focus on functionality while relying on the platform to enforce security. The cross-platform support and availability on Windows 365 further extend the reach of these security measures to both local and cloud-based agent deployments.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

What to watch next

Monitor the rollout of Microsoft Entra integration for distinguishing agent activity from user activity, which is described as coming soon. Watch for the availability of Intune management policies for MXC on Windows 11, which will allow IT administrators to enforce organizational constraints. Additionally, track the expansion of MXC support to more agent frameworks and the development of new containment backends to handle different isolation requirements.

The upcoming integration of Microsoft Entra to distinguish agent activity from user activity is a key development to watch. This will enable more precise security monitoring and governance, allowing organizations to attribute actions to specific agents and apply targeted policies. Its availability will likely coincide with the broader rollout of agent management capabilities in Microsoft Agent 365.

The release of Intune management policies for MXC on Windows 11 will be important for enterprise adoption. These policies will allow IT administrators to enforce organizational constraints on agent behavior, ensuring compliance with internal security standards. The timing and scope of this rollout will impact how quickly organizations can deploy MXC in managed environments.

The expansion of MXC support to additional agent frameworks and the development of new containment backends will determine the platform's versatility. As more agents and tools integrate with MXC, the ecosystem will become more robust, but it will also be important to monitor how well the system handles diverse workload requirements and isolation levels.

Related guides & quizzes

Found this useful?