Microsoft Open-Sources MXC: A Policy-Driven "Execution Container" for AI Agents Across Windows, macOS and Linux, Already Used by Codex and Copilot

On October 7 Microsoft announced general availability of Microsoft Execution Containers (MXC), open-sourced on GitHub under the MIT license. It is a containment layer for untrusted code and agent-generated workloads: developers declare in a unified JSON policy which files an agent can access, whether it can use the network, what processes it can run and whether it can touch the desktop, and because the policy sits outside the agent's control, the agent cannot grant itself more access. Under the hood it uses existing platform mechanisms: AppContainer on Windows, Seatbelt on macOS and Bubblewrap on Linux, with separate session and WSL containers on Windows 11 and an experimental microVM backend. A learning mode blocks and logs operations the agent attempted without permission so rules can be tuned. Microsoft says GitHub Copilot, OpenAI Codex, OpenClaw, Replit and LM Studio already support it, with Claude Code, Perplexity, Manus and others coming.

The problem it targets

When a coding agent works on your machine, the worry is that it reads files it shouldn't, connects where it shouldn't, or runs a command nobody expected. Today's usual answers are either a confirmation prompt at every step or opening everything up. On October 7 Logan Iyer, Microsoft's corporate vice president for Windows Platform + Developer, announced on the official blog that Microsoft Execution Containers (MXC) is generally available, aiming to answer the question with a single containment layer; the code is on GitHub under the MIT license.

How it works

Developers write a JSON policy declaring what the agent needs: which directories are readable, writable or invisible, whether inbound and outbound network (including loopback) is allowed, which commands it can launch and from which working directory, and whether it can touch the desktop UI. The key point is that the policy sits outside the agent's control, so neither the agent nor the code it generates can grant itself more access.

MXC then maps that policy onto each platform's existing isolation: AppContainer on Windows 11, Seatbelt on macOS and Bubblewrap on Linux, giving a lightweight process container on all three. Windows 11 adds two more: a session container that runs under a separate account and session with its own clipboard and input boundaries, and a WSL-based Linux container; a microVM backend with hardware isolation is still marked experimental. SDKs are available for Rust, .NET and Node.

Getting rules right the first time is rare, so there are three modes: enforcement; learning, which blocks unpermitted operations and records them in a JSON report; and permissive, which allows them but still records. Running real tasks in learning mode first, then tightening rules from the report, is the practical approach, though activity reports are currently supported only on Windows process containers.

Who has plugged in

Microsoft lists GitHub Copilot, OpenAI Codex, OpenClaw, Replit, LM Studio and Unsloth as already supporting it, and Nvidia has integrated OpenShell; Anthropic's Claude Code, Perplexity, Manus, Raycast and others are marked as coming. On the enterprise side, admins will be able to push constraints through Intune, and Entra and Agent 365 will separate agent activity from the employee's own.

For developers, this points toward agent isolation moving from each tool's own approach to a cross-platform, auditable standard. The repository is candid too: until rules are tuned, applications will likely hit access-denied errors, and each backend has different security properties that should be evaluated per workload.

via: Windows Developer Blog, GitHub repository