{
  "id": 13463431,
  "title": "Mxc: Microsoft Execution Containers version 1.0.0",
  "url": "https://urgent.news/2026/10/09/mxc-microsoft-execution-containers-version-1-0-0",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-09T06:52:49.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-driven-containment-for-ai-agents/"
  },
  "original_language": "en",
  "account": "Microsoft is rolling out Microsoft Execution Containers (MXC) version 1.0.0, a new containment layer for untrusted code and dynamically generated workloads. The goal is to help customers securely run and manage agents, without giving them unrestricted access that could introduce security risks.\n\nMXC allows developers and IT administrators to define the resources an agent can use, like files and network destinations. Containers enforce these policies at runtime, preventing the agent from accessing anything else unless explicitly granted access. This managed boundary ensures the agent can only perform tasks it was specifically designed for, without compromising other system components.\n\nWindows 11 will soon support MXC session containers, which run agents on a user's device in an OS-isolated session. This provides even stronger security for sensitive workloads, with its own local agent identity and isolated desktop, clipboard, UI, and input boundaries. MXC offers a spectrum of containment options, allowing developers to select the right level of isolation for each workload.\n\nWhile MXC provides many benefits, it's important to remember that an agent should never be its own security authority. It must run within a defined boundary, enforced independently of the agent itself. This is crucial when an agent is asked to perform tasks like updating a website, where it might need access to certain files and tools, but not to the entire system. By containing the agent's actions, developers can ensure the agent performs its intended function without inadvertently causing harm.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}