Microsoft Execution Containers (MXC) are now generally available on Windows 11, and they give you a way to limit what AI agents can touch on your PC. Microsoft announced the release at its October 7 Windows and Surface event. Think of it as a fence around each agent: it can only reach the files and networks a policy allows.
Quick facts to scan first:
- MXC is a policy layer that Windows enforces at runtime for AI agents.
- Microsoft says it is generally available on Windows 11 as of October 7, 2026.
- Containment options run from process isolation up to virtual machines and Windows 365 for Agents.
- Codex, GitHub Copilot, OpenClaw, Replit and LM Studio already support it.
If you only remember one thing, remember the first point. Everything else is detail on how that fence gets built.
Why AI agents need a fence in the first place
An AI agent is different from a chatbot. It does things: it opens files, runs code, and calls the network on your behalf. If it makes a mistake, or follows a bad instruction hidden in a web page, it can do real damage.
MXC is Microsoft’s answer. Developers describe what their agent is allowed to do, and Windows holds the agent to it. The agent doesn’t get to decide its own limits.
This matters more now that Windows itself is leaning on agents. Our look at the Copilot Autopilot feature shows how much these tools are expected to do for you.
How Microsoft Execution Containers work
According to Help Net Security, MXC is a policy-driven layer for AI agents on Windows and WSL. One SDK and one policy model map each workload to a suitable isolation method. Developers don’t have to wire up the low-level pieces themselves.
The same report describes three ideas behind it:
- Process isolation runs AI-generated code in a separate environment with limited file and network access.
- Session isolation keeps an agent away from your desktop, clipboard, and input devices.
- Each session gets its own identity, so admins can audit what an agent did and apply least-privilege rules through Entra and Intune.
The identity piece is the quiet winner. When an agent has its own identity, you can see its actions in a log instead of guessing.
Which containment level fits which job
| Level | What it does | Best for |
|---|---|---|
| Process isolation | Runs generated code in a separate environment with limited files and network | Everyday coding agents |
| Session isolation | Separates the agent from your desktop, clipboard and input | Agents that run in the background |
| WSL | Uses the Linux side of Windows as the boundary | Linux-based developer tools |
| Virtual machine | Hardware-backed separation | Sensitive data or untrusted code |
| Windows 365 for Agents | Moves the agent to a cloud PC | Managed company setups |
The list of levels comes from Windows Report. The “best for” column is our reading, not Microsoft’s wording. Microsoft hasn’t said which level applies in which case.
Who already supports AI agents on Windows with MXC
Windows Report says OpenAI Codex, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI already support Execution Containers. Anthropic’s Claude Code, Box, Manus, Perplexity and Raycast are expected to follow. Meta’s Muse will arrive as a native Windows app with MXC built in.
“Expected” is the key word for the second group. Nothing in the coverage gives a date for those apps.
If you run local agents, our guide to WSL containers on Windows 11 is a good companion read.
For companies, there is a management angle too. Help Net Security says Agent 365 plugs into the SDK and uses Microsoft Entra and Intune to enforce limits on specific agents. That means an IT team can apply the same kind of rules it already uses for people and devices, which is far easier than trusting every agent vendor to behave.
What we still don’t know
The launch coverage leaves gaps. There are no named Windows 11 builds, no hardware requirements, and no steps for turning MXC on as a regular user. Performance impact isn’t covered either.
The July preview also had limits. Session isolation supported only non-interactive sessions, and micro-VM and WSL Linux container support were still planned. Whether the October release closes those gaps isn’t clear from what we found, so check Microsoft’s own documentation before you rely on it.
Frequently Asked Questions
Do I need to turn on Microsoft Execution Containers myself?
Probably not. MXC is a tool for developers and admins, and the apps you use need to support it. No consumer on/off switch has been described.
Is MXC only for Windows?
No. Windows Report says it works across operating systems, though Windows gets deeper integration and more control options.
Does this make AI agents completely safe?
No. It limits the damage an agent can do, but a policy is only as good as its rules. A badly written policy still leaves holes.
Is Windows 11 search changing too?
Yes. The same event showed a search overhaul with quick actions, which we cover in our Windows 11 search actions post.
Our verdict: this is the most useful thing Microsoft announced for people who actually run agents. Flashy laptops get the headlines, but a fence you can enforce is what makes agents safe enough to try. Wait for your favorite agent app to add support, ask your IT team which containment level they plan to use, and treat any agent without it with caution.


Leave a Reply