Security
Microsoft Introduces Execution Containers to Enhance AI Security
During its Build 2026 conference, Microsoft introduced Execution Containers (MXC), a security toolkit aimed at preventing AI agents from accessing unauthorized data. The toolkit is designed to address the challenges posed by autonomous agents that can dynamically generate and execute code.
MXC functions as a policy-driven software development kit (SDK) that developers can integrate into their applications. It applies containment measures at the operating system level for both Windows and Windows Subsystem for Linux (WSL). Developers can define access rules using JSON or TypeScript, which the OS kernel enforces in real-time, ensuring that agents cannot bypass these restrictions.
Key Features of MXC
- Composable Sandbox: MXC allows developers to create customizable sandboxes where code can run without affecting the entire system.
- Isolation Tiers: The toolkit offers various levels of isolation, including process isolation for individual programs, session isolation for user sessions, and MicroVMs for cloud-based applications.
- Integration with Existing Tools: MXC is designed to work alongside Microsoft’s security products, including Entra, Defender, Intune, and Purview.
Notable early adopters of MXC include GitHub Copilot, OpenClaw, and NVIDIA’s OpenShell. The initiative reflects Microsoft's commitment to enhancing AI security, particularly as agents become more autonomous and capable of generating unpredictable code.
By implementing least-privilege enforcement, MXC ensures that each agent has access only to the resources necessary for its tasks, thereby improving security and accountability in AI operations.
FAQ
What are Execution Containers (MXC)?
Execution Containers (MXC) are a security toolkit introduced by Microsoft to prevent AI agents from accessing unauthorized data and to enhance overall AI security.
How does MXC enhance security for AI agents?
MXC enhances security by applying containment measures at the operating system level, allowing developers to define access rules that the OS kernel enforces in real-time.
What programming languages can be used to define access rules in MXC?
Developers can define access rules using JSON or TypeScript when integrating MXC into their applications.
What are the key features of MXC?
Key features of MXC include customizable sandboxes, various levels of isolation (process isolation, session isolation, and MicroVMs), and integration with existing Microsoft security products.
Who are some early adopters of MXC?
Notable early adopters of MXC include GitHub Copilot, OpenClaw, and NVIDIA’s OpenShell.