Microsoft has set rules for Agents, and Windows is poised to take control over AI.
On October 8 Beijing time, Microsoft announced that Microsoft Execution Containers (MXC), the execution isolation tool for AI Agents, is now officially available on Windows 11. Developers and enterprises can use it to restrict files, network and other resources accessed by Agents, and enforce these rules during runtime.
Microsoft also unveiled the first batch of products that support MXC, including OpenAI Codex, GitHub Copilot, OpenClaw, NVIDIA OpenShell, etc. Claude Code, Manus, Perplexity and other platforms plan to integrate MXC successively, and Meta Muse will also launch a Windows native application with MXC integration.
Figure: Microsoft launches Microsoft Execution Containers (MXC) to provide isolated execution environments for different AI Agents and restrict their access to resources such as files, emails, and networks
Pavan Davuluri, Executive Vice President of Microsoft Windows and Devices Business, summed up this direction with three key words: isolation, identity and manageability.
As AI begins to operate computers autonomously, the permission issue has become more complex. If a user allows an Agent to organize meeting materials, does that also mean it can read other emails, modify important files, or even send information to the outside?
Microsoft hopes to establish clearer boundaries for the autonomous execution of Agents through the operating system. While model companies including OpenAI and Anthropic are vying to build the operating system for the AI era, is the role of Windows also undergoing new changes?
01 How Does Windows Manage Agents?
The core idea of MXC officially released by Microsoft this time is to establish a security boundary for Agents to access system resources through an isolated execution environment.
According to the technical solution announced by Microsoft, enterprises can define the files and networks that Agents can access, and enforce these rules during operation. MXC also supports different levels of isolation, including process isolation, independent sessions, WSL containers, virtual machines, and Windows 365 cloud execution environments.
Traditional applications usually run according to the permissions granted by users. For example, a piece of software can apply for access to the camera, microphone or specific folder. After the user approves, the software can work within the corresponding permission scope.
The situation of Agents is more complicated. It receives a goal that needs to be planned by itself, and sometimes this goal is even relatively vague.
For example, a user asks an Agent to prepare for a customer meeting. It may first search for correspondence records in the mailbox, then open cloud documents to sort out requirements, then read local presentations, and finally create a meeting through the calendar. These steps may involve different applications, different data sources, and different levels of operational risks.
Microsoft explained in its official article on October 7 that traditional sandboxes are not specifically designed for Agents, because the isolation requirements of Agents may change with each prompt input and tool call.
MXC can be understood as delineating an execution scope for Agents. For example, an Agent responsible for organizing project materials can be restricted to reading files in a specified directory to avoid accessing irrelevant data. Microsoft also hopes to distinguish the operations of Agents from real users through independent identities, and integrate related activities into enterprise management systems such as Microsoft Agent 365 and Intune.
This follows the "least privilege principle" in the field of computer security, which means that a program only gets the permissions needed to complete its tasks. However, Agents will plan steps by themselves according to tasks, and permission requirements may also change continuously. How to restrict resource access without hindering task execution is a problem that Microsoft needs to solve. As for the operations completed by Agents through the graphical interface and the data flow across applications, other security mechanisms still need to cooperate.
02 Can Large Models Not Manage Themselves Properly?
Model companies such as OpenAI and Anthropic have set up different forms of security mechanisms for Agents, including sensitive operation confirmation, tool call restriction and abnormal behavior detection.
However, there is still a fundamental limitation for security rules at the model level: it requires the model to correctly understand and abide by these rules.
One typical risk is Prompt Injection.
Simon Willison, an independent developer and security researcher, proposed a risk combination called "Lethal Trifecta" in 2025: an Agent that can access private data, access untrusted content, and has the ability to send information to the outside at the same time.
When these three capabilities exist at the same time, attackers may induce Agents to read private data and send it out through malicious instructions in web pages, emails or documents.
Figure: Lethal Trifecta
For example, a user asks an Agent to read a web page material, but there is another hidden instruction in the web page, asking the Agent to find local sensitive files and upload them to an external server.
The user has never authorized this operation, but if the Agent mistakenly takes the content of the web page as an instruction and has corresponding file and network permissions, data leakage may occur.
This is also why model companies cannot only rely on prompts and security training.
In the technical article "How we contain Claude across products" released by Anthropic in May this year, the limitations of Agent security mechanisms in real products were further disclosed.
Anthropic found that Claude Code users will approve about 93% of permission requests. As confirmation pop-ups keep appearing, users may be less and less likely to carefully check each authorization. This means that even if the Agent asks the user before executing each step, it may not be able to effectively control risks.
Therefore, Anthropic has invested more engineering work in execution isolation, restricting the resources that Agents can access through sandboxes, virtual machines, file system boundaries and network egress control.
The company put forward an important distinction in the article: in addition to supervising what Agents actually do, it is also possible to restrict what they can do through the execution environment.
This idea is similar to the direction of Microsoft's launch of MXC this time. However, the isolation environment also has limitations. Anthropic disclosed in the article that as the capabilities of the model increase, Agents may find paths that developers did not expect, and even bypass the original isolation design in some test scenarios.
This shows that Agent security cannot be achieved by a single mechanism. The model needs to identify malicious instructions, applications need to restrict tool calls, and the operating system needs to enforce permission rules when actually accessing resources.
For Microsoft, this is a natural advantage to participate in Agent competition.
Model companies are good at enabling AI to understand tasks, plan steps, and select tools; operating system companies have long been responsible for managing application operation, user identity, file access and device resources.
However, Agents also pose new challenges to the operating system: should permissions be granted to an Agent, or to a specific task? Are different authorizations required for reading information and performing sensitive operations? When multiple Agents collaborate, can permissions be transferred between them?
For example, if a user allows an Agent to view shopping orders, it does not mean that it is allowed to cancel orders or complete payments; an Agent responsible for organizing internal materials should not transfer data to other Agents with external communication capabilities on its own.
There is still no unified solution to these problems. The significance of Microsoft's release this time lies in the attempt to put part of the control capability at the operating system level, adding constraints to the autonomous execution of Agents.
03 Is Windows Still Important?
In the past few years, one long-term change Windows has faced is that more and more users' work has been transferred to browsers and the cloud.
From office documents to enterprise management systems, many software no longer rely on traditional desktop applications. Users only need to open a browser to complete most of their work.
AI Agents may further change this relationship.
When users can directly tell AI "sort out all customer feedback from last week and generate a report", the process that originally required manually opening multiple software, searching for files and copying information can be handed over to Agents.
The direct interaction between users and software interfaces will decrease. This raises a question for the operating system: if people no longer operate applications in person in the future, what can Windows rely on to maintain its importance?
Perhaps becoming the operation and management platform for Agents is a feasible path.
On October 7, Microsoft has announced a very specific list of partners.
Products including OpenAI Codex, GitHub Copilot, OpenClaw, Replit, NVIDIA OpenShell, etc. already support MXC; Claude Code, Manus, Perplexity and other platforms plan to access, and Meta Muse will launch a Windows native application integrated with MXC.
This list is very interesting. It includes not only Microsoft's own products, but also model companies and Agent developers that have competitive relationships with Microsoft.
For Microsoft, the richer the Agents on Windows, the more opportunities it has to promote MXC to become an execution infrastructure widely adopted by developers. For model companies, accessing Windows' isolation mechanism may also reduce the cost of building a local execution environment from scratch.
There is room for cooperation between the two sides, but how to divide the user entry and system control rights in the future is still worth observing.
Microsoft also put forward the direction of "Hybrid Intelligence", allowing Agents to choose the execution location between local models and cloud models according to task requirements. Microsoft disclosed that Copilot+ PCs have already performed more than 2 trillion inferences locally every month, and GitHub also plans to test intelligent routing between local and cloud models.
This means that Microsoft hopes Windows can serve as both the execution environment for Agents and the local AI computing platform. As more tasks shift to local operation, the role of the operating system in computing resource scheduling, data protection and permission management may also further increase.
However, Microsoft may not be able to become the permission manager for all Agents. More and more Agents can run directly on the cloud, connecting enterprise software through APIs, without operating the user's local computer. Microsoft also said that MXC can be used across operating systems, but provides deeper integration on Windows.
Apple and Google are also competing for the system entry in the Agent era. Apple has the capabilities of software and hardware collaboration and end-side privacy, and Google masters the Android, browser and cloud AI ecosystem. Different manufacturers may attract developers through their respective execution environments, identity systems and permission interfaces.
This is similar to the app store competition in the mobile Internet era. In the past, operating systems influenced developers through application distribution and permission review; in the future, the execution environment of Agents may also become a new platform control point. But if there are too many restrictions, developers can still turn to browsers, cloud computers or other execution methods.
As Agents gradually take over software operations, the importance of Windows' traditional interface may decline, but a secure and reliable execution environment still has value. Microsoft hopes to consolidate the position of the operating system through this.
However, must the power to restrict AI belong to the operating system? Or will there be a better answer?
This article is from "Tencent Tech", written by Xiao Jing, edited by Xu Qingyang, and published with authorization by 36Kr.