The problem it targets
When a coding agent works on your machine, the worry is that it reads files it shouldn't, connects where it shouldn't, or runs a command nobody expected. Today's usual answers are either a confirmation prompt at every step or opening everything up. On October 7 Logan Iyer, Microsoft's corporate vice president for Windows Platform + Developer, announced on the official blog that Microsoft Execution Containers (MXC) is generally available, aiming to answer the question with a single containment layer; the code is on GitHub under the MIT license.
How it works
Developers write a JSON policy declaring what the agent needs: which directories are readable, writable or invisible, whether inbound and outbound network (including loopback) is allowed, which commands it can launch and from which working directory, and whether it can touch the desktop UI. The key point is that the policy sits outside the agent's control, so neither the agent nor the code it generates can grant itself more access.
MXC then maps that policy onto each platform's existing isolation: AppContainer on Windows 11, Seatbelt on macOS and Bubblewrap on Linux, giving a lightweight process container on all three. Windows 11 adds two more: a session container that runs under a separate account and session with its own clipboard and input boundaries, and a WSL-based Linux container; a microVM backend with hardware isolation is still marked experimental. SDKs are available for Rust, .NET and Node.
Getting rules right the first time is rare, so there are three modes: enforcement; learning, which blocks unpermitted operations and records them in a JSON report; and permissive, which allows them but still records. Running real tasks in learning mode first, then tightening rules from the report, is the practical approach, though activity reports are currently supported only on Windows process containers.
Who has plugged in
Microsoft lists GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth as already supporting it, and Nvidia has integrated OpenShell; Anthropic's Claude Code, Perplexity, Manus, Raycast and others are marked as coming. On the enterprise side, admins will be able to push constraints through Intune, and Entra and Agent 365 will separate agent activity from the employee's own.
For developers, this points toward agent isolation moving from each tool's own approach to a cross-platform, auditable standard. The repository is candid too: until rules are tuned, applications will likely hit access-denied errors, and each backend has different security properties that should be evaluated per workload.