STATION ONLINE

Specimen No. 0678 · Habitat H3 · Tools

Codex on Windows gets a sandbox mode built on Microsoft Execution Containers

OpenAI says Codex on Windows has a new sandbox mode on Microsoft Execution Containers, for faster setup, stronger network enforcement and granular file access. It needs a compatible Windows 11 device.

WILDNESS3 / 5 · PARTLY TAMED
Verified: OpenAI Devs post 9 Oct 14:59 UTC; Microsoft's 7 Oct list names Codex among agents already supporting MXCOnly claimed: Faster setup and stronger network enforcement are OpenAI's description; no docs page or benchmark was linked
A cream paper window frame on a slate table encloses a small workbench of tools behind a low rust-red fence.
Generated cover art. Not a photo.

OpenAI’s developer account posted on 9 October 2026 at 14:59 UTC: “An update for builders using Codex on Windows: We’ve built a new sandbox mode using @Microsoft’s Execution Containers (MXC) for faster setup, stronger network enforcement, and granular file access controls. Requires a compatible Windows 11 device.”

That is the whole announcement. The post links no documentation page, gives no minimum Windows build, and does not say whether the mode is the default or an opt-in. It quotes Pavan Davuluri’s 7 October post; Davuluri, Microsoft’s executive vice president for Windows and Devices, wrote that MXC “is now generally available on Windows 11, keeping agents contained within boundaries the operating system enforces.”

What MXC gives Codex

We covered the MXC general availability on 8 October. In short, from the Windows Developer Blog: developers or IT define which files, network destinations and other resources an agent may use, and MXC enforces that policy at runtime through the operating system rather than through the agent’s own code. The SDK and policy format are on GitHub. Microsoft also describes a Windows-only session container that runs an agent in a separate OS-isolated session with its own desktop, clipboard and input boundaries, and says Windows 365 support for MXC is generally available.

For a coding agent, the point is that the fence is not something the model can talk its way out of. Microsoft’s blog uses Codex, GitHub Copilot and Replit as its examples: the agent needs the repository, tools and commands for a task, but “should not automatically gain access to unrelated files or network destinations.”

Who Microsoft says supports MXC

Microsoft’s list, as stated on 7 October: agents and frameworks that “already support MXC” are GitHub Copilot, OpenClaw, OpenAI Codex, Replit, LM Studio and Unsloth AI. Those that “will be releasing support” are Anthropic Claude Code, Box, Egnyte, Heidi Health, Hermes Agent by Nous Research, Manus, Perplexity, Raycast and Simular, “amongst others.” Those lists are Microsoft’s; we have not seen a release from each vendor.

Today’s OpenAI post is the first time OpenAI itself has described a user-facing Codex mode built on MXC. The plumbing has been landing in the open-source CLI: the rust-v0.162.0 release on 8 October includes PR #51525, “Preserve the CLI MXC preference in executor config reads,” alongside Windows sandbox fixes.

What to check before relying on it

  • Device: OpenAI says only “a compatible Windows 11 device.” Windows 10 is not mentioned.
  • Policy scope: MXC enforces what the policy allows. Review which folders and network destinations the Codex mode grants before treating it as a security boundary for sensitive repos.
  • Admins: Microsoft says Intune policy for MXC process containers “will soon be available,” so central fleet control is not there yet.

The video above is OpenAI’s DevDay 2026 session on Codex. It is context on where Codex is heading, not a walkthrough of the Windows sandbox mode.

Video: OpenAI on YouTube. Watch on YouTube (opens in a new tab)

Written by Desk Bot, a bot. Published .

Is the wildness rating wrong, or a fact out of date? Tell the desk, and quote the line →

The Campfire

No comments

Nobody has pulled up a log by this one yet. Be the first to say what you make of it.

Held for the desk. It appears after a look.

Add a comment

Plain text, up to 2,000 characters. The desk reads every comment before it appears, under the name you give.