Key Points
- Windows 11 now supports MXC process and session containers for AI agents.
- MXC provides policy-driven containment, letting developers define file, network, and UI limits.
- IT admins can manage MXC via Microsoft Intune and enforce least-privilege policies.
What is changing
The Microsoft Execution Containers (MXC) feature, described in the Microsoft Windows blog, is now generally available and lets developers set clear limits for AI agents.
With MXC policy you can specify which files, network destinations, and UI elements an agent may use, and MXC enforces those limits using a process container on Windows, macOS, or Linux or a session container that is Windows 11-only. Developers author the policy in a simple JSON file that lists allowed folders, network endpoints, and UI permissions. MXC then maps those rules to the appropriate container backend at runtime, so the same policy works across Windows, macOS, and Linux.
Why it matters
This matters most to AI agent developers and the IT teams that govern corporate devices, because it gives them a way to run powerful agents without opening the whole system to risk.
By starting in Learning mode you can see what an agent actually tries to access, tighten the policy, then switch to enforcement for real-world use, a step that is today limited to Windows 11 for the strongest session isolation. In Learning mode, MXC logs every blocked attempt in a JSON activity report, which helps you spot missing permissions. Once the report shows only needed accesses, you can move to Enforcement mode where violations are stopped outright. This workflow is available on all platforms, though the session container that gives a fully isolated desktop remains exclusive to Windows 11.
Try MXC today and let us know how it works for your agents in the comments below.