Microsoft launches execution containers to keep AI agents on a short leash

Microsoft logo (public domain) via Wikimedia Commons

Microsoft launches execution containers to keep AI agents on a short leash

Microsoft Execution Containers give developers an OS-level sandbox for AI agents, with GitHub Copilot and OpenClaw among the early adopters

Microsoft wants AI agents to stop wandering into rooms they were never invited to. At its Build 2026 conference on June 2, 2026, the company unveiled Microsoft Execution Containers, or MXC, a security toolkit built to stop agents from reaching data they have no business touching.

Agents now write and run their own code on the fly, and the old security playbook was written for software that sat still.

What Microsoft actually shipped

MXC is a policy-driven SDK, a set of building blocks developers plug into their own software. It applies containment at the operating system level on both Windows and Windows Subsystem for Linux, known as WSL.

Developers write access rules for specific resources using JSON or TypeScript policies. The OS kernel then enforces those rules in real time, so the agent cannot simply talk its way past them.

Microsoft calls the underlying structure a “composable sandbox.” A sandbox is a walled-off space where code can run without touching the rest of the system. Composable means developers can mix and match the strength of those walls.

The isolation tiers span a wide range:

Advertisement
  • Process isolation: the lightweight option, fencing off an individual running program
  • Session isolation: a heavier boundary around an entire user session
  • MicroVMs: small virtual machines deployed in the cloud, the most separated tier on offer

MXC abstracts low-level isolation management away from developers, meaning fewer engineers will spend time debugging permission settings.

Who is already on board

GitHub Copilot is among the early adopters and has already put process isolation into its command line interface.

OpenClaw, an open-source AI agent framework, is also an early partner. So is NVIDIA’s OpenShell, giving the project a foothold beyond Microsoft’s own product family.

The roadmap points to tighter integration with Agent 365, Microsoft’s platform for agents. MXC is also set to work alongside the company’s existing security and management lineup: Entra, Defender, Intune, and Purview.

The product is still an early preview. Version 0.8.0, current as of September 2026, focuses on improvements to policy management and networking.

Microsoft is also clear that MXC is not a standalone product. It is positioned as a foundational primitive, a basic building block that other AI security tools can sit on top of.

Why agents broke the old security model

Traditional security models assume software behaves predictably. A program does what its code says, and administrators can review that code before it runs.

Autonomous agents do not play by those rules. They generate code dynamically, which means the instructions being executed may not have existed five minutes earlier.

MXC targets that gap with least-privilege enforcement. Each agent gets only the access it needs for the task at hand and nothing more.

It also binds agent actions to distinct identities. When something goes wrong, there is a clear record of which agent did what, which makes auditing far less of a guessing game.

Microsoft specifically names risks such as unauthorized data access and UI spoofing. The second one is a trick where an interface is faked to fool a user or system into trusting something it should not.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Microsoft launches execution containers to keep AI agents on a short leash
Microsoft launches execution containers to keep AI agents on a short leash

Microsoft Execution Containers give developers an OS-level sandbox for AI agents, with GitHub Copilot and OpenClaw among the early adopters

Microsoft logo (public domain) via Wikimedia Commons

Microsoft wants AI agents to stop wandering into rooms they were never invited to. At its Build 2026 conference on June 2, 2026, the company unveiled Microsoft Execution Containers, or MXC, a security toolkit built to stop agents from reaching data they have no business touching.

Agents now write and run their own code on the fly, and the old security playbook was written for software that sat still.

What Microsoft actually shipped

MXC is a policy-driven SDK, a set of building blocks developers plug into their own software. It applies containment at the operating system level on both Windows and Windows Subsystem for Linux, known as WSL.

Developers write access rules for specific resources using JSON or TypeScript policies. The OS kernel then enforces those rules in real time, so the agent cannot simply talk its way past them.

Microsoft calls the underlying structure a “composable sandbox.” A sandbox is a walled-off space where code can run without touching the rest of the system. Composable means developers can mix and match the strength of those walls.

The isolation tiers span a wide range:

Advertisement
  • Process isolation: the lightweight option, fencing off an individual running program
  • Session isolation: a heavier boundary around an entire user session
  • MicroVMs: small virtual machines deployed in the cloud, the most separated tier on offer

MXC abstracts low-level isolation management away from developers, meaning fewer engineers will spend time debugging permission settings.

Who is already on board

GitHub Copilot is among the early adopters and has already put process isolation into its command line interface.

OpenClaw, an open-source AI agent framework, is also an early partner. So is NVIDIA’s OpenShell, giving the project a foothold beyond Microsoft’s own product family.

The roadmap points to tighter integration with Agent 365, Microsoft’s platform for agents. MXC is also set to work alongside the company’s existing security and management lineup: Entra, Defender, Intune, and Purview.

The product is still an early preview. Version 0.8.0, current as of September 2026, focuses on improvements to policy management and networking.

Microsoft is also clear that MXC is not a standalone product. It is positioned as a foundational primitive, a basic building block that other AI security tools can sit on top of.

Why agents broke the old security model

Traditional security models assume software behaves predictably. A program does what its code says, and administrators can review that code before it runs.

Autonomous agents do not play by those rules. They generate code dynamically, which means the instructions being executed may not have existed five minutes earlier.

MXC targets that gap with least-privilege enforcement. Each agent gets only the access it needs for the task at hand and nothing more.

It also binds agent actions to distinct identities. When something goes wrong, there is a clear record of which agent did what, which makes auditing far less of a guessing game.

Microsoft specifically names risks such as unauthorized data access and UI spoofing. The second one is a trick where an interface is faked to fool a user or system into trusting something it should not.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.