Microsoft · 2026-10-07 · major
Microsoft Execution Containers (MXC) — Windows agent sandbox goes GA
Microsoft Execution Containers (MXC) is now generally available on Windows 11. It runs AI agents under a declared file, network and UI policy. Microsoft also showed local models on Windows, including a 3-bit MAI-Code-1.1-Flash.

Windows now gives AI agents an OS-enforced sandbox, and Microsoft is pushing more models to run locally on PCs.
Quick facts
| Maker | Microsoft (Windows) |
|---|---|
| Status | Generally available on Windows 11 |
| License | MIT (SDK, schema, samples) |
| SDKs | Rust, .NET, Node |
| Backends | Process, session, WSL containers; microVM (experimental) |
| Platforms | Windows 11, macOS, Linux |
What is it?
Microsoft Execution Containers (MXC) reached general availability on Windows 11 on 7 October 2026, at Microsoft's Windows and Surface event. Developers declare which files and network destinations an agent or its generated code may use, and Windows enforces that policy at runtime. The SDK and schema are open source under MIT at microsoft/mxc.
How does it work?
One JSON policy is mapped onto a backend per OS: AppContainer process containers on Windows, Seatbelt on macOS and Bubblewrap on Linux, plus Windows-only session containers, WSL containers and an experimental microVM. The policy sits outside the workload, so an agent cannot give itself more access. A learning mode blocks ungranted actions and writes a JSON report to help write the policy.
Why does it matter?
Agents that run shell commands on a laptop are a growing security risk, and MXC moves the guard rail into the operating system instead of each agent. GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth AI already support it, with Claude Code, Manus and Perplexity named as coming. The same event added llama.cpp support to Windows ML and showed local models such as MAI-Code-1.1-Flash and DeepSeek V4 Flash.
Who is it for?
developers shipping local agents, Windows IT and security teams
Frequently asked questions
- Which AI agents support Microsoft Execution Containers today?
- Microsoft says GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth AI already support Microsoft Execution Containers (MXC), and NVIDIA has integrated its OpenShell into MXC. Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent by Nous Research, Manus, Perplexity, Raycast and Simular are listed as adding support later.
- Does MXC work outside Windows?
- Yes, partly. The MXC process container runs on Windows 11, macOS and Linux, using AppContainer, Seatbelt and Bubblewrap. Session containers and WSL containers are Windows 11 only, and the microVM backend, for Windows 11 and Linux, is still marked experimental. The same JSON policy and SDKs work across all three operating systems.
- Can an agent change its own MXC permissions?
- No. Microsoft designed Microsoft Execution Containers so the policy stays outside the agent workload's control, which means an agent or the code it generates cannot grant itself extra file or network access. Organizations can add their own limits through management policy, and Microsoft says Intune control of MXC process containers is coming soon.
- What local models did Microsoft show alongside MXC?
- At the 7 October 2026 Windows event, Microsoft showed MAI-Code-1.1-Flash running locally with 3-bit quantization and a 256K context, DeepSeek V4 Flash (284B parameters) on RTX Spark, and an upcoming NVIDIA Nemotron model above 70B parameters in about 20GB. Windows ML, the on-device runtime, also gained llama.cpp support.
Try it
npm install @microsoft/mxc-sdk