Thursday, October 8, 2026Publish a press release →
Submit a Release
Security

Microsoft Makes AI Agent Sandboxing Generally Available on Windows 11

Microsoft Execution Containers let developers fence off which files and networks an AI agent can touch.

Alongside its new Surface hardware, Microsoft on Tuesday moved Microsoft Execution Containers (MXC) to general availability on Windows 11, giving developers a built-in way to run AI agents inside controlled environments.

MXC lets developers limit which files and network resources an agent can reach, a response to growing concern about autonomous agents taking unintended actions on users' machines.

Defender and admin controls

Microsoft paired the release with several security additions presented by Divya Venkataramu and Windows chief Pavan Davuluri:

  • Microsoft Defender will flag malicious prompts aimed at agents
  • IT administrators can monitor agent activity and risky behavior
  • Enterprise manageability for agents is coming to Microsoft 365

Developer tooling

Microsoft also announced an MXC Local Sandbox for writing and running code on a local machine, said llama.cpp is coming to Windows ML, and introduced "Canvas," a shared interface for agents and users to work together. A "Get Started" feature will help users set up popular AI agents without opening a terminal.

The push comes as agent security becomes a board-level issue. Insurance broker Aon recently reviewed more than 300 AI-related legal matters and found that crime, IP, cyber and tech E&O policies could all be triggered by agent misbehavior, according to the Financial Times.

More Microsoft news →

Related Coverage