Microsoft Execution Containers (MXC) are generally available as a policy-driven execution layer for untrusted or model-generated workloads, including AI agents, plugins, and tools. You declare the files, network destinations, commands, and desktop access a workload may use, and MXC enforces that boundary on Windows 11, macOS, or Linux. The policy sits outside the workload, so generated code cannot add permissions the policy left out. Intune policy for MXC process containers, and Entra attribution that separates agent activity from the signed-in user, are still described as coming soon. This article covers the Windows backends and the JSON policy.
Source