Microsoft Execution Containers explained and what it means for Windows 11 users

Microsoft Execution Containers puts a security boundary around AI agents so they can work without unrestricted access to your Windows PC.

Microsoft Execution Containers
Microsoft Execution Containers / Image: Mauro Huculak & Microsoft
  • Microsoft Execution Containers limits AI agents by controlling which files, networks, processes, and desktop resources they can access on Windows 11.
  • The security boundary sits outside the agent, so the AI cannot simply grant itself additional permissions to complete a task.
  • MXC works behind the scenes and is designed to be integrated into AI apps, with support already available for agents including Copilot, Codex, OpenClaw, Replit, and LM Studio.
  • Windows is building a broader agent security model around containment, identity, and manageability as AI agents become more capable.

AI agents are becoming more capable of doing things for users instead of simply answering questions. An agent can read files, run commands, use applications, access websites, and perform other tasks on Windows 11.

Those capabilities also create new security risks. If an AI agent has the same access as the person using the computer, a mistake, compromised tool, or malicious code could affect files and resources unrelated to the task.

Microsoft is addressing this problem with Microsoft Execution Containers (MXC), a policy-driven security framework that controls what AI agents and other untrusted workloads can access. However, the question still remains. What exactly is MXC, and what does it mean for regular Windows users?

What is Microsoft Execution Containers (MXC)?

Microsoft Execution Containers (MXC) is a security framework that lets developers and organizations run AI agents and other untrusted workloads in a controlled execution environment.

Instead of letting an agent automatically use everything available to the signed-in user, developers and network administrators can define what it can access.

For example, a coding agent could have permission to read and modify files in a specific project folder and run development tools such as Git. The same agent could be prevented from accessing personal files, connecting to unapproved network destinations, or interacting with the desktop.

The security policy exists outside the AI agent, so the agent cannot simply give itself additional permissions.

Why does Microsoft need MXC for AI agents?

AI agents differ from traditional software because they can dynamically decide which actions to take to complete a task.

Imagine asking a coding agent to fix a website. The agent needs access to the website’s source code and development tools. It might also need to read a server configuration file.

The agent should not be allowed to modify that production configuration. Without a separate security boundary, however, the agent could decide that changing the configuration is the easiest way to complete the task.

MXC is designed to prevent this type of behavior. If the agent, generated code, plugin, or tool tries to perform an operation outside its allowed boundary, the containment layer can block it.

Does MXC give an AI agent more access to my computer?

Developers or administrators define which resources an agent needs. MXC then creates a containment environment that limits the workload to those resources.

For example, an agent could be allowed to access a project folder and Git while being blocked from your Documents folder, unrelated files, unapproved network destinations, or parts of the desktop.

The necessary permissions depend on how the application and organization configure the agent.

Does MXC protect my personal files?

It can, when an AI application supports MXC and the appropriate policies are configured.

An AI agent may need access to one folder to complete a task, but it does not necessarily need access to every file on the computer.

Microsoft Execution Containers lets developers and administrators set narrower boundaries, so an agent can work with files in a project folder while being prevented from accessing unrelated personal files elsewhere on the computer.

The goal is least-privilege access. An agent gets only the permissions it needs to do its job, without automatically gaining access to everything the user can access.

Do I need to configure MXC myself?

Usually, no. MXC is primarily a technology for developers and network administrators. Developers can integrate the MXC software development kit into their applications and define the resources their workloads require.

Organizations can then apply additional restrictions through management policies.

For regular users, Microsoft Execution Containers run behind the scenes. You use the AI application normally while its execution environment enforces the defined security boundaries.

Which AI applications support MXC?

Microsoft says several AI agents and frameworks already support MXC, including:

  • GitHub Copilot
  • OpenAI Codex
  • OpenClaw
  • Replit
  • LM Studio
  • Unsloth AI

The company also says support is coming to Anthropic Claude Code, Box, Egnyte, Heidi Health, Manus, Perplexity, Raycast, and others.

MXC isn’t limited to Microsoft’s own AI agents. The framework lets different developers use the same containment model for their AI workloads.

What can MXC control?

Microsoft Execution Containers can control several parts of an agent’s execution environment.

  • Files can be restricted to specific locations and permissions, such as read-only or read and write access.
  • Network access can control inbound and outbound connections, including connections through the host’s loopback interface.
  • Processes can control how a workload starts, including its command, arguments, working directory, and environment.
  • User interface access can determine whether a workload can interact with the Windows desktop and related UI resources.
  • Containment determines the environment in which the workload runs, such as a process or session container.

What types of containers does MXC use?

MXC provides several containment options depending on the workload and required level of isolation.

A process container provides lightweight isolation for responsive workloads. On Windows 11, it uses AppContainer, while MXC uses the appropriate sandbox technology on macOS and Linux.

A session container is available on Windows 11 and provides stronger separation by running the agent in a separate Windows session with its own identity, desktop, clipboard, UI, and input boundaries.

A WSL container uses Windows Subsystem for Linux and is designed for Linux-focused agent tools and workloads.

A MicroVM is available experimentally on Windows 11 and Linux. It provides hardware-enforced isolation and full Linux workload compatibility for higher-risk workloads.

Regular users generally won’t need to choose between these options. The developer or administrator chooses the containment model that fits the workload.

Is MXC the same as Windows Sandbox?

No. Windows Sandbox provides a temporary, isolated Windows environment where you can run apps and files separately from the main operating system.

MXC is a policy-driven execution framework that controls what an AI agent or other workload can access while it runs.

The distinction is important. Windows Sandbox gives the user an isolated environment, while MXC gives an application or agent a controlled security boundary.

Can an AI agent bypass MXC?

Microsoft Execution Containers is designed to enforce security policy outside the agent itself. For example, an agent could be allowed to read a configuration file but not modify it. If the agent attempts to write to the file, MXC can block the operation.

The agent cannot simply change its own policy to grant itself permission.

MXC does not make an AI agent completely safe. Microsoft describes containment as one part of a broader security model that also includes agent identity and management.

What happens if an agent needs something MXC blocks?

The agent may be unable to complete the task if it lacks the required permission. Microsoft provides three operating modes to help developers create and test policies:

  • Enforcement mode blocks operations outside the policy.
  • Learning mode blocks and records unapproved operations in an activity report, helping developers identify missing permissions.
  • Permissive mode allows the workload to continue while recording resources the policy would have blocked.

These modes let developers determine exactly what an agent needs before applying a stricter production policy.

Does MXC know whether an action came from me or an AI agent?

The company is also working on separating agent activity from user activity.

Windows 11 will soon allow Microsoft Entra to distinguish agent activity from user activity in Microsoft Agent 365.

The distinction could help administrators identify which agent performed an action, investigate suspicious behavior, and restrict an individual agent without necessarily blocking the employee’s access to the same resources.

Does MXC only work on Windows 11?

No. MXC’s process containers work across Windows 11, macOS, and Linux. Other containment options are platform-specific.

Get the Pureinfotech newsletter

Expert Windows guides, practical tips, and the latest updates that make your PC easier to use, delivered to your inbox

Windows 11 supports process, session, and WSL containers, while MicroVM support is currently experimental on Windows 11 and Linux.

Microsoft also says MXC support is generally available with Windows 365, allowing agents to run on Cloud PCs using the containment framework.

Does MXC affect ordinary Windows users today?

Potentially, but mostly behind the scenes. You probably won’t see a Microsoft Execution Containers setting on Windows 11 that you need to turn on.

Instead, MXC can become part of the AI app you use. If an app supports MXC, its agent can run with a defined set of permissions instead of automatically receiving unrestricted access to your computer.

Why should Windows users care about MXC?

The biggest change with AI agents is that they can do things rather than simply tell you how to do them.

An agent that can edit files, run commands, interact with applications, or access online services has more potential to cause damage if something goes wrong.

MXC is Microsoft’s attempt to put a security boundary around those capabilities.

The basic idea is simple. An AI agent should get the access it needs to complete a task, but not unlimited access to everything the user can access.

Regular users do not need to understand the underlying container technology or configure policies themselves. The key question is whether the AI applications they use adopt these safeguards and how they configure permissions.

Microsoft’s broader AI security strategy

Microsoft Execution Containers is one part of Microsoft’s broader approach to securing AI agents.

Would you trust an AI agent with access to your Windows 11 PC?

Voting closes: October 15, 2026 1:00 pm

The company describes three key areas:

  • Containment limits what an agent can access and do.
  • Identity separates an agent’s activity from a person’s.
  • Manageability gives organizations tools to control access and monitor agent activity.

MXC provides the containment layer, while the software giant is expanding agents’ identity and management capabilities.

For Windows users, the goal is to make AI agents capable of performing more useful tasks without requiring unrestricted access to the entire computer.

As AI agents become more capable, an important security question will no longer be only “What can this AI do?” It will also be “What is this AI allowed to do on my computer?”

And Microsoft Execution Containers is Microsoft’s answer to the second question.

About the author

Mauro Huculak is a Windows How-To Expert and founder of Pureinfotech in 2010. With over 23 years as a technology writer and IT Specialist, Mauro specializes in Windows, software, and cross-platform systems such as Linux, Android, and macOS.

Certifications: Microsoft Certified Solutions Associate (MCSA), Cisco Certified Network Professional (CCNP), VMware Certified Professional (VCP), and CompTIA A+ and Network+.

Mauro is a recognized Microsoft MVP and has also been a long-time contributor to Windows Central.

You can follow him on YouTube, Threads, BlueSky, X (Twitter), LinkedIn and About.me. Email him at [email protected].

Comments

Join In