Enterprise Adoption 2026-10-08

Microsoft Makes Execution Containers Generally Available: Agent Sandboxing as an OS Feature, With Intune and Entra Controls Coming

At its October 7 Windows event, Microsoft made MXC -- a policy layer that confines what an AI agent can touch on Windows, macOS and Linux -- generally available, with Codex, GitHub Copilot and Replit already integrated and Claude Code among those promised. Nadella's 'hybrid intelligence' pitch and NVIDIA's RTX Spark laptops were the stage; the containment model is what developers and IT will actually have to work with.

On October 7, 2026, at a Windows and Surface event in San Francisco, Microsoft announced general availability of Microsoft Execution Containers (MXC), first shown as a preview SDK at Build in June. The Windows Developer Blog post, by Windows Platform CVP Logan Iyer, describes MXC as "a policy-driven execution layer for untrusted code or dynamically generated workloads." Windows 365 support is also generally available, so the same agents can run on Cloud PCs.

What developers are building against

  • One policy, several sandboxes. Developers declare the files, network destinations, processes and UI an agent needs in a JSON schema, and MXC maps it to a backend: a process container (AppContainer on Windows, Seatbelt on macOS, Bubblewrap on Linux), a session container that runs under a separate Windows account and desktop, a WSL container, or a MicroVM, which is marked experimental.
  • The agent can't widen its own box. "The policy remains outside the agent workload's control, so the agent or generated code cannot grant itself additional access."
  • Learning mode for least privilege. On Windows only, a process container can record what a workload tried to reach in a JSON activity report, so teams can write a tight policy without guessing.
  • Adoption. GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth AI already support MXC, and NVIDIA has integrated OpenShell. Microsoft lists Anthropic's Claude Code, Box, Egnyte, Manus, Perplexity and Raycast among those that "will be releasing support."

The enterprise piece -- mostly "coming soon"

Intune policy "will soon be available" to manage MXC process containers on Windows 11, letting IT layer organisational limits over a developer's policy so the same agent can run under different company boundaries. Microsoft also says Windows will soon let Entra "distinguish agent activity from user activity" in Agent 365, its control plane for agents. On stage, Satya Nadella described Windows as becoming a "hybrid intelligence" system mixing cloud and local models, and Copilot head Jacob Andreou said lighter Copilot tasks can now run without the cloud. NVIDIA's RTX Spark chip in the $2,599 Surface Laptop Ultra (on sale October 16) is the hardware those local models are meant to run on.

What remains uncertain. Microsoft's own wording is careful: the container "is designed to prevent" disallowed operations, and "each containment backend has distinct security properties." The two controls enterprises most need -- central management and separate agent identity -- are announced, not shipped.

Analysis: the adoption constraint here is change management more than technology. Teams can start using learning mode now to see what their coding agents actually touch, but should keep existing endpoint and data-loss controls until Intune management and Entra agent identity arrive. Microsoft's guidance that agents "should not silently fail" when a policy blocks them is a useful test to apply to any agent product being evaluated.

MXC turns agent sandboxing into a cross-platform OS feature with a declared policy the agent can't change, and major coding agents already use it; but Intune management and Entra agent identity are still 'coming soon', and Microsoft frames the containers as 'designed to prevent' rather than guaranteed boundaries.