Microsoft announced at Build 2026 the introduction of Microsoft Execution Containers (MXC) — a policy-driven execution layer for AI agents on Windows and WSL.

MXC provides a composable sandbox with a single SDK and policy model mapping workloads to appropriate isolation mechanisms. Agent 365 natively integrates with the SDK, using Microsoft Entra and Intune to enforce constraints on specific AI agents.

The early preview includes process isolation and session isolation. Partners include NVIDIA, OpenAI, OpenClaw, Hermes, and Manus. GitHub Copilot CLI already uses MXC.

Future plans include micro-VM support and Linux container support via Agent 365 integration with Entra and Intune.

The MXC repository (microsoft/mxc) is MIT-licensed and notes this is an early preview — profiles should not yet be treated as formal security boundaries.