Agentic AI

Microsoft Execution Containers: Windows 11 finally confines AI agents by policy

On October 7, Microsoft announced general availability of Microsoft Execution Containers (MXC) on Windows 11, a framework for running AI agents (or any untrusted code) with tightly bounded permissions.

The principle

The rules live outside the agent, so it can't grant itself more access. A developer or admin lists the allowed files and network destinations, and the containment layer blocks the rest. Example given: an agent can reach a project folder and Git, but not Documents, unrelated files, or unapproved domains.

Isolation levels

| Level | Platforms | Use | |---|---|---| | Process container | Windows 11, macOS, Linux | general case | | Session container | Windows 11 | long-running agents, desktop separate from the user | | WSL container | Windows 11 | Linux workloads | | MicroVM | experimental | maximum isolation |

Admins can enforce policies through Intune. Per press reports, several products already support it (Codex, GitHub Copilot, Replit, LM Studio, Nvidia's OpenShell), with others expected to follow.

Why it matters even if you're not on Windows

The model is the one recommended for any agent:

  1. Policy external to the agent, never in its prompt.
  2. Allowlist of files and domains rather than a denylist.
  3. Isolation level proportionate to risk (process, session, VM).

On a Linux VPS you get the equivalent with an unprivileged container, read-only limited volumes and filtered egress. See also our article on the lessons of the "rogue agents" case.

Limits

  • The strongest protection (session) is specific to Windows 11; the MicroVM is still experimental.
  • It all depends on agent vendors adopting it: an agent that doesn't go through MXC isn't confined.
  • Some local Copilot features are still arriving over the coming months, and sources differ on the exact scope of general availability.

Sources: Windows Developer Blog, Pureinfotech, Windows Report, ITdaily, explainx.ai.