Microsoft Execution Containers: Policy-driven containment for AI agents

Written By

published

October 7, 2026

Agents are unlocking enormous productivity gains for customers, but their ability to work across files, networks, and applications can introduce new security risks. This can leave customers feeling like they only have two choices: give agents unrestricted access and hope nothing goes wrong or block them and lose the productivity benefits they provide. Neither option is acceptable.

That’s why we’re building Windows platform capabilities to help run and manage agents more securely, starting with:

  • Containment: limiting what an agent can access and do.
  • Identity: distinguishing an agent’s activity from a person.
  • Manageability: giving organizations the tools to govern access and monitor agent activity.