Microsoft Made Its AI Agent Sandbox Generally Available on Windows 11. The Intune Policy That Lets IT Set the Boundary Has No Date.
On Wednesday, October 7, Microsoft held a Windows and Surface event in San Francisco and put Jensen Huang on stage next to Satya Nadella. The hardware got the applause: RTX Spark laptops, led by a Surface Laptop Ultra that Microsoft says runs models above 120 billion parameters locally, starting at $2,599.
The more important announcement was a security layer. In a Windows Developer Blog post, Logan Iyer, Corporate Vice President for Windows Platform and Developer, wrote that "Microsoft Execution Containers (MXC), now generally available, provides the containment layer" for AI agents on Windows 11. That is an operating system vendor putting a general availability label on a sandbox built specifically for agents.
Read the same post to the end, though, and the pieces that let a company's IT department actually decide what those containers allow are still in the future tense. "Intune policy will soon be available to manage MXC process containers used by MXC-integrated agents on Windows 11," Iyer wrote. No date.
What MXC Actually Does
MXC is a policy layer between an agent and the machine it runs on. A developer declares what a workload needs, which files and which network destinations, and Windows enforces that boundary at runtime. The open source repository on GitHub is MIT licensed and ships SDKs for Rust, .NET and Node.
The design principle is the right one. "An agent cannot be its own security authority," Iyer wrote, and the policy "remains outside the agent workload's control." A model that decides mid-task it needs your SSH keys cannot grant itself access to them.
There are four containment backends. A process container uses AppContainer on Windows, Seatbelt on macOS and Bubblewrap on Linux. A session container runs the agent under a separate Windows account and session. A WSL container covers Linux tooling. A microVM backend provides hardware-enforced isolation on Windows 11 and Linux, and Microsoft labels it experimental.
Each policy runs in one of three modes. Enforcement blocks anything not granted and writes no report. Learning blocks it and logs it to a JSON activity report. Permissive allows it and logs it. Per Microsoft, only process containers on Windows can produce that activity report today.
Shipped Versus Promised
Here is everything Microsoft and its partners put on the table on Wednesday, sorted by what you can use today.
| Item | Status per Microsoft | Date |
|---|---|---|
| MXC on Windows 11 | Generally available | October 7 |
| Windows 365 support for MXC | Generally available | October 7 |
| MicroVM backend | Experimental | None given |
| Intune policy for MXC process containers | "Will soon be available" | None given |
| Entra separating agent activity from user activity | Coming soon | None given |
| Agent 365 controls for local agents | Announced | None given |
| Claude Code, Perplexity, Manus, Raycast support | "Will be releasing support" | None given |
| Copilot local context, actions and models | Expected on Copilot+ PCs | "Coming months" |
| Surface Laptop Ultra (RTX Spark), from $2,599 | Pre-order | Available October 16 |
| Surface RTX Spark Dev Box, from $5,999 | Pre-order, U.S. only | Ships in November |
| DGX Station for Windows (Dell, HP) | Announced | Later this year |
Two of eleven rows are generally available software. Two more are hardware you can pre-order today. Every row that would give an administrator central control over local agents is undated.
Who Is Inside the Container
Microsoft's list of agents that already support MXC reads like a roll call of the coding market: OpenAI's Codex, GitHub Copilot, OpenClaw, Replit, LM Studio and Unsloth AI, with Nvidia's OpenShell integrated into the layer. The list of those that "will be releasing support" includes Anthropic Claude Code, Box, Egnyte, Heidi Health, Nous Research's Hermes Agent, Manus, Perplexity, Raycast and Simular. Meta's Muse for Windows is coming as a native app with MXC built in.
So on day one, the coding agents from OpenAI and Microsoft's own GitHub are inside the boundary, and Anthropic's is not yet. We would not read that as a snub. Microsoft lists Claude Code among the partners releasing support, and gave no date for it. But a developer running Claude Code on an RTX Spark laptop on October 16 will do so without MXC.
OpenClaw is the most interesting name on the list. On February 19, Microsoft's own Defender security research team said OpenClaw was not appropriate for a standard personal or enterprise workstation and recommended a dedicated virtual machine or a separate physical system. Seven and a half months later the same company is shipping a native Windows gateway for OpenClaw with MXC integration. The backend that most resembles that February advice, the hardware-isolated microVM, is the one Microsoft still labels experimental.
127 Days From Preview to GA
Microsoft introduced MXC on Tuesday, June 2, at Build, as an "early preview" of the SDK. That post already said administrators would be able to use Intune policies to require MXC isolation with guardrails such as filesystem rules. It took 127 days to get the containment layer to general availability. The Intune piece that was described in June is still not shipping.
That ordering matters more than it looks. In our reading, until Intune policy lands, the boundary on a given machine starts from what the integrating agent's developer declared. The policy sits outside the model's control. It does not yet sit centrally in the customer's.
The developer repository adds one more caution. Its README says the executor's --audit flag turns off all sandbox security for the workload being analyzed, and adds: "Never use it to run untrusted code." Learning mode, which keeps enforcement on, is the safer way to discover what an agent needs.
Why the Hardware Raises the Stakes
The RTX Spark machines are what turn this from a policy footnote into a deployment question. Microsoft's Surface post by Brett Ostrum says the Surface Laptop Ultra can run AI models exceeding 120B parameters locally, with up to 128 GB of unified memory and up to 1 petaflop of AI performance. The footnote matters: that petaflop is theoretical FP4 throughput using sparsity.
Pre-orders opened Wednesday for RTX Spark systems from ASUS, Dell, HP, Lenovo, MSI and Surface, with availability starting Friday, October 16. Pavan Davuluri, Microsoft's Executive Vice President for Windows and Devices, wrote that over 40 percent of laptops being built for business are now Copilot+ PCs.
Put those together and the shape is clear. Microsoft wants agents running locally, on business laptops, with persistent access to files and networks, and it shipped the sandbox for them nine days before the hardware arrives. What it has not shipped is the management plane a fleet administrator would use to set the rules across a thousand of those laptops.
Our Take
MXC is the most serious OS-level answer to agent containment we have seen, and we think the design is right. A policy outside the agent, enforced by the OS, with a learning mode that produces an audit trail, is what agent sandboxing should look like.
But "generally available" is doing a lot of work in this announcement. For a consumer or a solo developer, MXC on October 7 is real protection, as long as their agent is on the supported list. For an enterprise, the product that matters is MXC plus Intune plus Entra attribution, and two of those three carry no date. We would not let a fleet of RTX Spark laptops run local agents against production credentials on the strength of developer-set policy alone.
Microsoft's next big stage is Ignite in November. That is where we expect either a date for Intune policy or a quiet slide into 2027. Three signposts we are watching:
- A dated general availability for Intune policy on MXC process containers, ideally announced at Ignite in November.
- Claude Code and Perplexity shipping MXC support, and whether integrators default to Enforcement mode or leave customers in Permissive.
- The microVM backend dropping its experimental label, which would finally match the isolation Microsoft itself recommended for OpenClaw in February.
For earlier context, see our coverage of RTX Spark at Computex, Apple's undated fix for agent disk access and Plugin4Shell.
Sources: Windows Developer Blog: Microsoft Execution Containers, Windows Experience Blog: Building Windows for hybrid intelligence, Surface Blog: Pre-order our most powerful Surface devices ever, Windows Developer Blog: Windows platform security for AI agents (June 2), microsoft/mxc on GitHub, NVIDIA Blog, Microsoft Security Blog: Running OpenClaw safely, Unite.AI, Petri and Wccftech.
