Microsoft Execution Containers (MXC)

Eintrag zuletzt aktualisiert am: 02.06.2026

Sandbox für KI-Agenten, Isolation auf Prozesslevel
angekündigt am 2.6.2026 auf Microsoft BUILD 2026

Details

"Microsoft Execution Containers: A policy-driven execution layer that lets developers declare what an agent can access (e.g., files, network) with containment boundaries enforced at runtime. MXC offers a spectrum of isolation semantics that are dynamically composable based on intent and risk, available in early preview."

Quelle: Microsoft

"- Agent 365 native integration with MXC enables agents running on Windows to start secure and stay secure. Integration will deliver Defender, Entra, Intune and Purview protections so security and IT teams can constrain and secure local agents to prevent enterprise risk, available in preview in July.
  • OpenClaw runs natively on Windows leveraging MXC - The Windows node and gateway run contained, so your system stays secure. You can easily install and use OpenClaw in Windows with its own companion app and set up your own claws or connect to existing ones, available in open-source. We are invested in continuing to make OpenClaw run securely on Windows.
  • NVIDIA is bringing OpenShell to Windows built on MXC - Integrating MXC via OpenShell provides developers with an easy-to-deploy package for autonomous, always-on agents safely."

Quelle: Microsoft

"It's critical to contain agent impact without limiting productivity gains. That’s why we are introducing Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for agents across Windows and WSL. Developers declare what an agent can access, like files and networking related policies configured in Intune, and MXC enforces those boundaries at runtime. Windows delivers a composable sandbox spectrum through MXC — a single SDK and policy model that maps to the right isolation construct for any agent workload.
  • Fast process isolation (adopted by GitHub Copilot CLI) and session isolation separates the agent's execution from the user's desktop, clipboard, UI and input devices, and critically, binds the agent to a strong user identity — mitigating UI spoofing, input injection and cross-session data leakage. Process isolation and session isolation will be available to Windows Insiders shortly after Build.
  • Windows 365 for Agents, now generally available, extends containment beyond the local device and agents run in an Intune-managed Cloud PC, fully separate from the user's machine.
  • Micro-VMs, Linux containers and MXC integration for Windows 365 for Agents are currently on our roadmap as additional MXC containment capabilities.
  • Agent 365 layers Entra and Intune policy on top so IT can govern containment centrally while developers choose the guardrail weight their workload demands."

Quelle: Microsoft