AIComputers

Microsoft's MXC AI Agent Isolation Tool Is Now Generally Available

Microsoft Execution Containers isolate AI agents from the rest of a system, letting developers set permissions, restrict network access and block sensitive documents.

Microsoft announced that Microsoft Execution Containers (MXC), its tool for isolating AI agents from the rest of a system, is now generally available. The company said the approach limits the damage that accidents or malicious prompts can cause.

With MXC, developers can run agents in their own session with their own identity rather than under the user's account. Developers and administrators can also set permissions and policies that control what an AI agent is allowed to do.

Those controls extend to data and connectivity. Sensitive documents can be restricted so an agent cannot interact with them, and network access for an agent can be specified or limited.

Microsoft Defender can detect malicious prompts before they execute. MXC is open source on GitHub and works across Linux, macOS and WSL.

Microsoft is not alone in taking this approach: OpenClaw, NVIDIA OpenShell and GitHub Copilot CLI already employ agent isolation, according to howtogeek.com.

Why isolation matters

Most AI agents on Windows currently run as the user, which gives them the same access to files as that user. MXC is designed to put a boundary between the agent and everything else on the machine.

Quick answers

What is Microsoft Execution Containers (MXC)?

It is Microsoft's tool for isolating AI agents from the rest of a system, so accidents or malicious prompts have limited impact. It is open source on GitHub.

Which platforms does MXC support?

Microsoft says MXC works across Linux, macOS and WSL.

Can administrators restrict what an AI agent does?

Yes. Developers and admins can set permissions and policies, restrict sensitive documents from agent access, and specify or limit the agent's network access. Microsoft Defender can also detect malicious prompts before they execute.

Source