Sunday, October 11, 2026
News

Microsoft ships containers that limit what AI agents can touch on Windows 11

GitHub Copilot, OpenAI Codex and LM Studio already run inside them. Central management through Intune is not ready yet.

A person using a Windows 11 laptop on their lapWindows / Unsplash
Photo: Windows / Unsplash

Microsoft made Microsoft Execution Containers, or MXC, generally available on Windows 11 on October 7. MXC lets developers and IT administrators set hard limits on what an AI agent running on a PC can do: which files it can read and write, which network connections it can open, which processes it can start and whether it can interact with the user's desktop.

The limits are enforced outside the agent. As eSecurity Planet put it, an AI agent "cannot simply grant itself additional file or network access."

How it works

Limits are written in a JSON configuration file, and developers build them in with an SDK. MXC can contain an agent in several ways:

Container type Platforms Status
Process containers Windows 11, macOS, Linux Available
Session containers (separate Windows account and session) Windows 11 Available
WSL containers Windows 11 Available
MicroVM containers (hardware virtualization) Windows 11, Linux Experimental

Each container runs in one of three modes. Enforcement blocks anything outside the policy. Learning blocks it too and writes a JSON report of what was blocked, which helps when writing a policy for a new agent. Permissive mode only records what would have been blocked and lets it through, so it gives no protection.

Which agents use it

eSecurity Planet lists GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI as already supporting MXC. Anthropic's Claude Code, Box, Egnyte, Manus and Perplexity are among those planning support. Support does not mean every feature of an agent runs inside a container, so check with each vendor.

What is missing

For IT teams, the gaps matter as much as the launch. Central management of MXC process containers through Intune is "not yet generally available" and will arrive in a future release. Agent identity, which Microsoft plans to build with Entra and Microsoft Agent 365, is still being developed. Microsoft has not given dates for either.

Until Intune support lands, MXC policies are set per agent and per device, which is hard to run across a fleet.

What IT teams should do

  1. List the AI agents running on company PCs today, starting with coding assistants on developer laptops.
  2. Ask each vendor whether its agent supports MXC and which parts of it run inside the container.
  3. Pilot learning mode on a few developer machines to see what file and network access each agent really uses.
  4. Don't leave agents in permissive mode on production machines. It logs but blocks nothing.
  5. Watch for the Intune release before planning a fleet-wide rollout.

Sources