NewsLayer.com

Microsoft Execution Containers: Policy-driven containment for AI agents

Agents are unlocking enormous productivity gains for customers, but their ability to work across files, networks, and applications can introduce new security risks. This can leave customers feeling like they only have two choices: give…

Windows Blog

Publisher

Oct 7, 2026 at 9:45 PM UTC · 9 分钟阅读

Microsoft Execution Containers: Policy-driven containment for AI agents
NewsLayer editorial artwork
翻译中…

Agents are unlocking enormous productivity gains for customers, but their ability to work across files, networks, and applications can introduce new security risks. This can leave customers feeling like they only have two choices: give agents unrestricted access and hope nothing goes wrong or block them and lose the productivity benefits they provide. Neither option is acceptable.

That’s why we’re building Windows platform capabilities to help run and manage agents more securely, starting with:

  • Containment: limiting what an agent can access and do.
  • Identity: distinguishing an agent’s activity from a person.
  • Manageability: giving organizations the tools to govern access and monitor agent activity.

Microsoft Execution Containers (MXC), now generally available, provides the containment layer. Developers and IT administrators define the resources, like files and network destinations an agent can use and MXC uses the appropriate container to enforce those policies at runtime.

Windows will also soon enable Microsoft Entra to help distinguish agent activity from user activity, ensuring users can remain productive even when agent access needs restrictions and extend Microsoft Agent 365 controls to local agents on-device, enabling IT teams to manage MXC containers, apply policies, and monitor agent activity.