What shipped
Microsoft made Microsoft Execution Containers generally available on 7 October, alongside its Windows and Surface event in San Francisco. MXC is a policy layer that decides what a piece of code — in practice, an AI agent — is allowed to touch while it runs. Logan Iyer, corporate vice president for Windows Platform and Developer, described it as the containment part of the company’s agent platform work, sitting alongside identity and manageability. It is generally available on Windows 365 Cloud PCs as well.
The premise is that an agent is untrusted code. It is generated or steered at runtime by a model reacting to text it did not write, which makes it closer to a downloaded script than to an installed application. Windows has had no standard way to treat it as one.
Four boxes and three modes
A developer picks a containment level. A process container is the lightest and the only cross-platform option: AppContainer on Windows 11, Seatbelt on macOS, Bubblewrap on Linux. A session container, Windows 11 only, runs the agent under a separate Windows account with its own desktop, clipboard and input boundaries. A WSL container gives it a Linux environment, also Windows 11 only. A MicroVM, marked experimental and offered on Windows 11 and Linux, provides hardware-backed isolation.

On top of that sit three operating modes. Enforcement applies the policy and blocks anything not granted, producing no report. Learning blocks the same things and writes what it blocked into a JSON activity report. Permissive allows ungranted access but records it, which is how a policy gets written in the first place. Activity reports are produced only for Windows process containers.
The policy is a JSON document with a shared schema and a multi-language SDK. It covers five areas: the containment environment, the process (command, arguments, working directory, environment), the file system (readable, writable and blocked locations), the network (inbound and outbound access, including loopback) and the user interface (desktop access). Organisations can layer their own constraints through Microsoft Intune, so the same agent runs under different rules at different companies.
Who is already in the box
Microsoft lists NVIDIA, through its OpenShell integration, along with GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio and Unsloth AI as using MXC today. Announced as coming: Anthropic’s Claude Code, Box, Egnyte, Heidi Health, the Hermes Agent from Nous Research, Manus, Perplexity, Raycast and Simular.
That list is the argument. These are tools that until now ran with whatever privileges the person who launched them had, on machines that also hold source code, credentials and customer records. Naming the files an agent may read and the hosts it may reach is a narrow fix, but it is the fix that matters when an agent reads a web page written by someone else.

What is not there yet
Intune management of MXC process containers on Windows 11 — including control over container creation requests and resource boundaries — is listed as coming. So is Microsoft Entra support for telling agent activity apart from user activity in Microsoft Agent 365, and the extension of Agent 365 controls to local on-device agents. Several of the named partner agents are still on the same list.
The announcement states no licence and no version number. The SDK, schema, documentation and samples are in a public GitHub repository. NVIDIA, announcing the same event, said MXC works with Microsoft Security and Agent 365 so agents can be secured, observed and governed.
What to watch
Whether the enterprise controls arrive before the agents do. A containment layer an administrator cannot see into or constrain centrally is a developer feature; one wired into Intune and Entra is a security control. Microsoft has shipped the first and promised the second.