getnews.online

Microsoft makes Execution Containers generally available to fence in AI agents

MXC lets developers set what files and networks an agent may use. The rules sit outside the agent, so it cannot give itself more access.

4container types

Hype check

Hype3
Real5
Underrated

Quieter than it deserves. This one matters more than the coverage suggests.

Your call: hype or real?

Real = it will matter in daily use. Hype = louder than it is. One vote, and it can’t be changed.

Why it matters

that run code need clear limits. MXC gives builders one policy format across Windows, macOS and Linux.

For most people

Skip: nothing changes for you.

The details

  • Policies cover files, network, processes and the user interface.
  • Backends: process container, session container, WSL container and MicroVM (experimental).
  • Modes: enforcement, learning and permissive.
  • Agents already supporting MXC include GitHub Copilot, OpenAI Codex, Replit and LM Studio.
  • Intune policy is coming soon, and Entra support is coming soon.
Try itBuilders running agents should try the learning mode first.

Receipts

The company or lab said it. Primary source linked. Open the sources and check us.

Written with the help of AI tools and checked against the sources above. How we work

Get the daily brief by email

One email each morning. Unsubscribe with one click.

See a mistake? Tell us and we’ll fix it.