Photo by Icons8 Team on Unsplash. Source: https://unsplash.com/photos/woman-sitting-while-using-laptop-CrW-TbykPBQ (Unsplash License).

Microsoft made Microsoft Execution Containers generally available on 7 October. Agent containment stopped being a framework feature and became a Windows one.

  • Policy is authored outside the agent and enforced at runtime, so an agent cannot widen its own permissions.
  • Four backends range from a process container built on AppContainer, Seatbelt and Bubblewrap to an experimental MicroVM with a hardware-enforced boundary.
  • A session container runs an agent under a separate Windows account with its own desktop, clipboard and input.
  • Codex, GitHub Copilot, OpenClaw, Replit, LM Studio and Unsloth AI already support it.
  • Intune policy management and Microsoft Entra agent identity are listed as coming, not shipped.
  • Containment only helps when the agent people actually run respects it, and the coming list is longer than the shipped one.

Read the full analysis of what moved into the operating system

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.