Microsoft says AI agents need stricter controls as they gain access to enterprise data and systems, but defining those boundaries may prove more challenging than it sounds.
Key Takeaways:
As AI agents gain access to files, applications, and networks, organizations face the challenge of granting enough permissions for productivity without increasing the risk of errors, misuse, or security compromises. Microsoft Execution Containers (MXC) is Microsoft’s attempt to solve that problem by putting AI workloads inside policy-enforced security boundaries.
As organizations adopt AI agents for coding, automation, and other business tasks, those tools frequently operate with the same permissions as the user who launched them. An agent may need access to repositories, development tools, or company resources to complete a task, but without clear restrictions, it could access unrelated systems or make changes that were never intended. Microsoft argues that agents cannot be trusted to regulate themselves and need externally enforced controls.
However, keep in mind that restricting agents too heavily can limit their usefulness, and granting broad access increases the risk of accidental changes, data exposure, or unauthorized actions. Microsoft uses the example of a coding agent that needs to read server configurations but could incorrectly decide to modify production settings, which potentially causes outages or operational issues.
To address these concerns, Microsoft has made Microsoft Execution Containers (MXC) generally available for commercial customers. This platform allows developers and IT admins to define exactly which files, network destinations, tools, and system resources an AI workload can access. Those policies are enforced by the operating system, which prevents AI-generated code or plugins from elevating their own permissions.
MXC supports multiple containment models, including lightweight process containers, isolated Windows session containers, Linux-based WSL containers, and experimental MicroVMs for higher-risk workloads. Organizations can choose the isolation level that best matches the sensitivity of a given task.
The platform also gives administrators controls over file access, networking, user-interface interaction, and execution settings. Moreover, Microsoft plans to integrate MXC with Microsoft Intune, which enables enterprises to apply organization-wide policies and governance controls to agent workloads running on Windows devices.
Microsoft acknowledges that defining least-privilege policies can be challenging because developers may not initially know every resource an agent requires. To ease deployment, MXC includes learning and permissive modes that help organizations observe agent behavior and refine policies before enforcing them. However, IT admins will need to invest time in configuring, testing, and maintaining those controls to avoid blocking legitimate agent activity.
Going forward, Microsoft also plans to add agent-specific identity and attribution capabilities through Microsoft Entra and Microsoft Agent 365. The goal is to let security teams track and manage AI agents separately from human users, which reduces the impact of compromised or misbehaving agents while maintaining employee productivity.