Microsoft launches MXC Execution Containers to sandbox AI agents across Windows, Linux and macOS
TheKanter · x · 2026-10-11
Microsoft has made Microsoft Execution Containers (MXC) generally available, a policy-driven containment layer for running AI agents securely.
- Granular control: Developers can use a unified JSON configuration and SDK to restrict which files, networks and system resources an agent can access — e.g. letting an agent edit a project and run tools while blocking access to personal files or write operations on read-only configs.
- No self-escalation: Restrictions are enforced outside the agent's control, so it cannot grant itself extra permissions.
- Cross-platform: Leverages platform-native sandboxes (like Bubblewrap on Linux) across Windows, Linux and macOS.
- Ecosystem: GitHub Copilot, OpenAI Codex and Replit already support it, with Claude Code support in progress.
Microsoft frames this as the first pillar of a broader agent platform strategy alongside Identity (distinguishing agent activity from humans) and Manageability (enterprise governance and monitoring).
More from coding & agent
- GPT Researcher crosses 30k GitHub stars, built and maintained almost entirely by community — EdenEmarco177 · 2026-10-11
- shadcn: AI hasn't sped up abstraction design yet, it just helps me fail faster — shadcn · 2026-10-11
- Free 7-week production Agentic RAG course hits 9.7k stars on GitHub — mdancho84 · 2026-10-11
- Arize AI shows how agents can self-learn from production traces to fix their own bugs — AI Engineer · 2026-10-11
- Power User Runs AI Coding Agent 24/7, Burns Through Weekly Limit in Two Days — gandamu_ml · 2026-10-11
- Hallucinated model name sat in codebase for months, caught 6 days before a deprecated model shutdown — Trout_dev · 2026-10-11