What happened
On Oct 7, 2026 Microsoft made Microsoft Execution Containers (MXC) generally available: a policy-driven execution layer where developers/IT declare the files and network destinations an agent may use, and MXC enforces that boundary at runtime via process/session/WSL/microVM backends on Windows 11, macOS and Linux. Windows 365 (Cloud PC) support is also GA, and Entra-based agent-identity differentiation plus Agent 365 controls for local agents are upcoming.
Why it matters
This is the OS-level containment answer to rogue or over-privileged AI agents: an agent can no longer grant itself access, because policy sits outside its control. It gives Windows an on-by-default boundary for local coding/automation agents, lowering the risk that prompt-injected agents modify production config or exfiltrate files.
Applicability
Enterprise security and platform teams standardizing on Windows should evaluate MXC policies for coding agents (Claude Code, Codex, Copilot) before granting them file/network scope; adopt at GA now, pilot in preview with Entra identity separation.