Microsoft releases MXC 1.0 to contain AI agents with policy-enforced containers on Windows, macOS, and Linux
- Microsoft Execution Containers (MXC) is now generally available as the containment layer for AI agents, enforcing file and network policies that developers and IT administrators declare.
- The policy stays outside the agent's control, so generated code, plugins, or the agent itself cannot grant extra access, and MXC maps a unified JSON configuration schema onto each platform's backend.
- Only Windows offers a session container, which runs an agent in a separate OS-isolated session with its own local agent identity, desktop, clipboard, and input boundaries.
- Microsoft says Windows will soon use Microsoft Entra to tell agent activity apart from user activity and will extend Microsoft Agent 365 controls to local agents so IT teams can manage containers and monitor activity.
- Commenters point out that the backends give different security guarantees, and that LPAC on Windows makes many executables, PowerShell among them, fail at startup.
Hacker News 의견들
Good idea, and enterprise buyers are going to eat this up.
Can I use this as a generic app permissions boundary, or do I have to fake it as an agent? I just want my music player locked out of my SSH keys. My guess is this gets gated to corporate licenses and the rest of us get nothing.
Locking down npm install is the one I want most. I wonder if this can plug into dev containers so the dev container runs in stricter isolation.
We've been bad at permissioning for years, and piling more complexity onto the security model isn't fixing it. Connect to Jira and you get a different identity system and resource model. When something fails, they just say it wasn't secured correctly. We need a rethink from the root.
Microsoft's enterprise permissions for SharePoint and Azure are fine, but Excel, VSCode, and Outlook still give you a 'Do you trust this?' binary choice that unlocks everything.
I skimmed the backend docs and they read like an LLM told to make things work at all costs. The bubblewrap section is a stream of consciousness. I have almost no confidence in the results.
I've watched this project for a while and tried several versions. It looks sloppy and the docs are basically nonexistent. The abstraction is a good idea, but it's far from a 1.0.
The biggest news is that the W11 25H2 August cumulative update lets anyone set up App containers without admin rights, and MXC is built on top of that. It's unstable right now, but it's a first step.
That's huge for enterprise. Setting up the ChatGPT desktop on Windows Sandbox for users is a slog at the moment, and Intune plus identity through Agent 365 is coming too.
I want a simple way to restrict an app's read/write access to one directory. I don't think MXC does that. Happy to be told otherwise.
You can launch arbitrary exes with MXC, but the backends give different guarantees. LPAC on Windows makes a lot of exes fail at startup, PowerShell for one.
I tried it. This isn't a 1.0 release, it's an early tech preview.