<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg" -->

---
title: Running AI agents in sandboxes with Microsoft Execution...
description: Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework for running AI agents securely on Windows, macOS, and Linux. It...
canonical: https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Running AI agents in sandboxes with Microsoft Execution Containers | daily.dev
og:description: Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework for running AI agents securely on Windows, macOS, and Linux. It...
og:url: https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg
og:image: https://api.daily.dev/og/posts/p0S0UIskG.png
og:image:alt: Running AI agents in sandboxes with Microsoft Execution Containers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Running AI agents in sandboxes with Microsoft Execution Containers

**[InfoWorld](https://daily.dev/sources/infoworld)** · 8 min read · 1 upvotes · 0 comments

## Summary

Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework for running AI agents securely on Windows, macOS, and Linux. It uses hardware virtualization and JSON-based policies with a default-deny posture to restrict what agent code can access, integrating with technologies like Windows Sandbox, Hyperlight microVMs, and Windows 365 for Agents Cloud PCs. GitHub Copilot has already adopted MXC to provide sandboxed CLI sessions with restricted file system and outbound-only network access. The latest release, MXC 0.8.0, improves policy management and networking support, though the project remains an early-stage preview likely to change significantly before a final release.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.infoworld.com/article/4215416/running-ai-agents-in-sandboxes-with-microsoft-execution-containers.html>

## Questions this post answers

### What is Microsoft Execution Containers (MXC) and what does it do?

Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework written in Rust that isolates AI agents on Windows, macOS, and Linux using hardware virtualization. It uses JSON-based policies with a default-deny stance to restrict file system and network access, managing a sandbox lifecycle of provision, start, execute, stop, and de-provision, so developers can lock down untrusted agent code.

_Track how sandboxing frameworks for agents evolve by following AI agent security coverage on daily.dev._

### How does GitHub Copilot use MXC sandboxing in CLI sessions?

GitHub Copilot is an early adopter of MXC, offering a sandboxed mode enabled via a single command in any CLI session once experimental mode is turned on. This restricts file system access to the PATH, working directory, Windows temp folders, and user profile, and allows outbound-only network connectivity, with a config option to open additional directories if wider access is needed.

_Developers weighing agent tooling safety can follow Copilot sandbox updates on daily.dev._

### What does MXC version 0.8.0 change compared to earlier releases?

MXC 0.8.0 offers the most up-to-date set of policies for managing sandbox guardrails around agents, and improves networking support with better security and improved tooling for delivering policies across different sandbox environments. It requires a Rust toolchain and a recent Node.js build plus npm to build from the repository rather than relying solely on release binaries.

_Keep up with fast-moving agent sandboxing releases like this one on daily.dev._

## Similar posts on daily.dev

- [Windows Platform Security and the Race to Secure AI Agents](https://daily.dev/posts/windows-platform-security-and-the-race-to-secure-ai-agents-l771ipwbm) · InfoQ · 0 upvotes · 0 comments

---

Tags: [#github](https://daily.dev/tags/github), [#ai-agents](https://daily.dev/tags/ai-agents), [#rust](https://daily.dev/tags/rust)

[View this post on daily.dev](https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Running AI agents in sandboxes with Microsoft Execution Containers","url":"https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg"},"datePublished":"2026-09-03T09:05:43.870Z","dateModified":"2026-09-03T09:09:08.009Z","description":"Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework for running AI agents securely on Windows, macOS, and Linux. It...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fce184e3f5794dbdc1ffb540f814651a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fce184e3f5794dbdc1ffb540f814651a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"InfoWorld","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"InfoWorld","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/bf6d68a999064029b0bb09aa6268f1f3","url":"https://daily.dev/sources/infoworld"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"github,ai-agents,rust","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"InfoWorld","item":"https://daily.dev/sources/infoworld"},{"@type":"ListItem","position":3,"name":"Running AI agents in sandboxes with Microsoft Execution Containers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/running-ai-agents-in-sandboxes-with-microsoft-execution-containers-p0s0uiskg#faq","mainEntity":[{"@type":"Question","name":"What is Microsoft Execution Containers (MXC) and what does it do?","acceptedAnswer":{"@type":"Answer","text":"Microsoft Execution Containers (MXC) is an open-source, cross-platform sandboxing framework written in Rust that isolates AI agents on Windows, macOS, and Linux using hardware virtualization. It uses JSON-based policies with a default-deny stance to restrict file system and network access, managing a sandbox lifecycle of provision, start, execute, stop, and de-provision, so developers can lock down untrusted agent code. Track how sandboxing frameworks for agents evolve by following AI agent security coverage on daily.dev."}},{"@type":"Question","name":"How does GitHub Copilot use MXC sandboxing in CLI sessions?","acceptedAnswer":{"@type":"Answer","text":"GitHub Copilot is an early adopter of MXC, offering a sandboxed mode enabled via a single command in any CLI session once experimental mode is turned on. This restricts file system access to the PATH, working directory, Windows temp folders, and user profile, and allows outbound-only network connectivity, with a config option to open additional directories if wider access is needed. Developers weighing agent tooling safety can follow Copilot sandbox updates on daily.dev."}},{"@type":"Question","name":"What does MXC version 0.8.0 change compared to earlier releases?","acceptedAnswer":{"@type":"Answer","text":"MXC 0.8.0 offers the most up-to-date set of policies for managing sandbox guardrails around agents, and improves networking support with better security and improved tooling for delivering policies across different sandbox environments. It requires a Rust toolchain and a recent Node.js build plus npm to build from the repository rather than relying solely on release binaries. Keep up with fast-moving agent sandboxing releases like this one on daily.dev."}}]}
```

