News

Microsoft Execution Containers Ship on Windows 11

Giancarlo Viterbo
·
October 8, 2026  ·  5 min read
Add as Preferred Source on Google
microsoft windows nvidia rtx spark 9

Microsoft has made Microsoft Execution Containers generally available on Windows 11, turning its agent sandbox from a developer preview into a shipped operating system feature. The announcement came at the company’s Windows and Surface event in San Francisco on October 7.

The pitch is narrow and specific: AI agents that can read files, run tools and take actions need privileges, and today they borrow the user’s. Microsoft is instead giving them their own identity, their own sandbox and their own audit trail, enforced by Windows rather than by the app asking nicely.

What Microsoft Execution Containers actually do

MXC is a policy-driven execution layer. Organisations define which files and networks an agent is allowed to reach, and Windows enforces those policies at runtime, so an agent only touches what has been approved. Microsoft introduced the SDK at its Build conference in June as an early preview covering Windows and WSL.

microsoft windows nvidia rtx spark 9

It is not a closed component. The project is published on GitHub under the MIT licence, and the repository has been public since February 2026. It supports several containment backends, and on Windows the spectrum runs from a process boundary up through session isolation, WSL containers, virtual machines and Windows 365 for Agents.

The second half is attribution. On stage, Windows chief Pavan Davuluri said every action an agent takes “should be attributed to the agent not to you”, which Microsoft enforces at the operating system level. That distinction is what makes the security response usable: when Microsoft Defender detects a hijacked agent, an administrator can cut that agent off without locking the human out of the same files.

microsoft windows nvidia rtx spark 8

Microsoft demonstrated exactly that. A test website was seeded with instructions designed to hijack a coding agent; Defender blocked the action and flagged the agent, while the presenter’s own access to the same documents stayed intact. Microsoft Execution Containers handle the enforcement. Policy and lifecycle are managed through Agent 365 with Microsoft Entra and Intune, and the developer documentation frames it as identity, isolation and governance for local agents.

The partner list is the part that makes it a platform rather than a feature. Microsoft says agents already supporting MXC include Codex from OpenAI, GitHub Copilot, OpenClaw, Replit, LM Studio, OpenShell from NVIDIA and Unsloth AI. It lists Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent by Nous Research, Manus, Perplexity, Raycast and Simular as bringing support. Meta’s personal agent, Muse for Windows, is coming as a native Windows app with MXC integration of its own.

microsoft windows nvidia rtx spark 17

Both chief executives framed it in the same terms. “We needed to make the desktop the most secure place for agents to execute,” Microsoft CEO Satya Nadella said in his fireside chat with NVIDIA CEO Jensen Huang, who added that “just as Windows and DirectX revolutionized how applications were built, MXC is going to revolutionize how agents are built and deployed.”

Hybrid intelligence: the other half of the announcement

Microsoft also pushed what it calls hybrid intelligence, meaning an agent runs work on the PC when cost or privacy favours it and reaches the cloud only for the hardest tasks. Windows ML is the runtime that spreads models across GPU, NPU and CPU, and Microsoft said it is bringing llama.cpp to it, which opens the door to open-source models on day one.

microsoft windows nvidia rtx spark 13

The local model roster is now specific. MAI Code 1.1 Flash, a coding model with 137 billion total and 6.8 billion active parameters, was quantised to three bits, cut roughly 80 percent in size and runs with a 256K context window on the device. NVIDIA’s upcoming Nemotron has more than 70 billion parameters at two bits in just over 20GB, and DeepSeek V4 Flash is a 284-billion-parameter model Microsoft is fitting onto local RTX Spark machines. A year ago, Microsoft noted, that class of capability was exclusive to cloud models.

Routing between those local models and the cloud arrives with GitHub’s HydraFusion, which Microsoft says comes to the GitHub Copilot app, the Copilot CLI and Visual Studio Code in experimental preview later in October. The app-side of this lands on Windows 11 too: taskbar search gains thousands of quick actions this fall, and Copilot is being given local context over your files, local actions on your machine, and the option to delegate work down to a local model.

microsoft windows nvidia rtx spark 14

The hardware was already announced

Worth being clear about, because the coverage this week did not always say so. Surface Laptop Ultra was unveiled on May 31 ahead of Computex, not introduced at this event. What October 7 added was the price and the preorder window.

The machine is built around NVIDIA RTX Spark with up to 128GB of unified memory, full CUDA support and one petaflop of AI compute, which Microsoft says is enough to run up to 120-billion-parameter models locally. It carries a 15-inch mini-LED PixelSense Ultra touchscreen rated at up to 2,000 nits peak HDR, and a user-serviceable storage drive.

Surface Laptop Ultra, one of the PCs Microsoft Execution Containers will govern
Surface Laptop Ultra carries NVIDIA RTX Spark. Microsoft is positioning Windows 11 as the layer that contains what agents do on machines like it. Image: Microsoft

Microsoft opened preorders for Surface Laptop Ultra and partner RTX Spark laptops from ASUS, Dell, HP, Lenovo and MSI. The company said the machines begin shipping on October 16. A DGX Station for Windows, which NVIDIA says runs on a GB300 Grace Blackwell Ultra Desktop Superchip with 748GB of coherent memory and up to 20 petaFLOPS of FP4 compute, was previewed for the first time for models at the trillion-parameter scale.

Why this matters in the Philippines

This is a deployment problem before it is a consumer one. Philippine enterprises and outsourcing teams are the audience for agent policy, and until now an agent running on a Windows desktop had the same access as the person sitting in front of it. Giving agents a separate identity is what lets an IT team say yes to running them at all.

The local angle on hybrid intelligence is cost. Running inference on the device removes the per-token charge entirely, which matters more in a market where AI subscriptions are priced in dollars against peso budgets. Microsoft has not announced Philippine pricing or availability for any of the hardware shown.

windows agent platform featured
windows agent platform featured

We have followed the hardware this platform is meant to run on, including the Snapdragon X Elite Googlebook and the RTX Spark laptops ASUS has already announced for the Philippines. Whether MXC ends up adopted as widely as it is promoted is a different question, and one worth watching once agents are actually deployed at scale.

Giancarlo Viterbo

Founder, Chief Editor, and Sales Lead · Blip Media Digital Marketing Consultancy Inc · 2201 articles published

Giancarlo Viterbo is a Filipino Technology Journalist, blogger and Editor of gadgetpilipinas.net, He is also a Geek, Dad and a Husband. He knows a lot about washing the dishes, doing some errands and following instructions from his boss on his day job. Follow him on twitter: @gianviterbo and @gadgetpilipinas.

View all articles →

Related News