On October 7, 2026, Microsoft made Microsoft Execution Containers (MXC) generally available, including support on Windows 365. For Windows developers and IT teams, the release provides a policy-driven way to restrict agent workloads on PCs and Cloud PCs. Separately, Microsoft announced on-device coding-model access and a later-October preview of local/cloud routing in GitHub Copilot.
The practical starting point is containment on a supported machine, without waiting for new inference hardware. Model placement and tool permissions are separate decisions. A cloud model can request work inside a local containment boundary. Moving the model onto the PC does not, by itself, restrict the tools it uses. This follows from the Windows and GitHub execution architecture.
What is available, and what is still coming
MXC and Windows 365 support: generally available. Microsoft lists GitHub Copilot, OpenClaw, Replit and LM Studio among existing integrations; Claude Code support is forthcoming. This is Microsoft’s integration-status report, not confirmation of every client version, default or supported backend.
Local MAI Code 1.1 Flash: Microsoft says the model can now be downloaded and run locally. Its experimental integration in the Copilot app, CLI and VS Code is planned by the end of October. This reporting did not verify a versioned weights download, model license or complete standalone installation path.
Automatic local/cloud routing: experimental preview is planned for later October. That is distinct from the existing cloud HydraFusion research preview. Final local-preview account eligibility, client requirements and fallback behavior were not established.
Enterprise management extensions: Entra-based agent attribution, expanded Agent 365 controls for local agents and Intune management of MXC process containers are described as coming soon. MXC’s GA status does not make those controls available today.
Choose the execution boundary for the workload
MXC is an SDK that applications embed, with Rust, .NET and Node interfaces. The application selects a backend, supplies policy and launches the workload. For builders, this offers a common integration surface; it does not make every backend’s isolation properties identical.
Use the launch containment matrix to shortlist a backend, then check the chosen application and host. The decisions below are architectural guidance, not compatibility-test results.
Workload or requirement | Backend to evaluate | Boundary and readiness |
|---|---|---|
Repository edits, builds and tool execution | Process container | Lightweight process sandboxing on Windows 11, macOS and Linux. It is not a separate VM. |
Long-running Windows desktop automation | Session container | A distinct Windows account and session separates desktop, clipboard, UI and input from the interactive user. Windows 11 only. |
Linux-first build or agent toolchain on Windows | WSL container (WSLc) | A Linux execution environment through WSL. Check its own permissions and host prerequisites. |
A requirement for hardware-backed isolation | MicroVM | The launch matrix lists Windows 11 and Linux support as experimental. Do not substitute process containment for a required virtualized boundary. |
Windows 365 support extends the choice to a Cloud PC; it does not decide where inference runs. Check the MXC process/session OS support matrix and the client’s requirements separately. For example, GitHub’s app/CLI configuration guide specifies Windows 11 25H2 with KB5124010 or later, or 26H1 with KB5124006 or later, plus BaseContainer support. A generic SDK-supported host is not automatically a supported Copilot configuration.
Check what the integration actually contains
The joint Windows/GitHub post says Copilot uses the BaseContainer tier of MXC’s ProcessContainer on Windows. When enabled, shell commands and default local MCP and language-server processes use that process boundary. Built-in file tools instead check policy inside the agent harness; remote MCP servers are outside the local process sandbox. An SDK’s session or VM options therefore should not be assumed to protect every Copilot operation.
Network guarantees also need client-specific evidence. The MXC backend documentation describes native Windows Filtering Platform controls for supported contracts. Current Copilot documentation still says Windows host rules and proxying depend on programs honoring proxy settings. Do not infer that the SDK’s capabilities remove a documented application-level limitation.
For enablement, defaults and managed enforcement, use the RohitAI Copilot local-sandboxing guide.
Size the local-model pilot for a complete session
Microsoft recommends more than 120 GB RAM for best performance with local MAI Code 1.1 Flash. That is a recommendation, not a verified universal minimum. The engineering post describes a mixture-of-experts model with 137 billion total parameters and 6.8 billion active parameters; the smaller active count is not a basis for sizing resident model memory.
Microsoft reports a 53 GB on-device model footprint and 75.5 GB peak memory use at 256K context on Surface Laptop Ultra. Calculation using the vendor’s GB figures: 75.5 − 53 = 22.5 GB above the model footprint, roughly 42.5% of that footprint. This illustrates session overhead in that reported setup, not a fixed allowance for every workload. The source does not establish that all of the difference is key-value cache. See the published memory results.
Budget for the operating system, development tools, runtime and growing context together. A procurement pilot should evaluate complete coding tasks at expected context sizes; weight fit alone does not establish acceptable latency, task quality or concurrency.
The Surface announcement lists Laptop Ultra with up to 128 GB unified memory, a US-dollar starting MSRP of $2,599 and availability beginning October 16. The entry price is not a verified quote for the suitable-memory configuration. Surface RTX Spark Dev Box is listed at $5,999 MSRP, with US-only preorders and November shipping. Obtain the actual configuration price before comparing local and cloud costs.
Local inference is not an offline workflow
The announced Copilot integration offers automatic local/cloud placement or explicit selection of a local model, including through Windows ML or an OpenAI-compatible local endpoint. Automatic placement can involve remote inference. Choosing a local endpoint still leaves separate decisions about networked tools, remote MCP services, dependency downloads and credentials.
For an offline requirement, define which inputs must already be present and which connections must be blocked. For a hybrid workflow, decide which code and tool outputs may reach a remote model before enabling routing. Evaluate the whole data path, not only the model-picker label.
A practical adoption sequence
Pilot containment first: choose one repository or desktop task, identify writable outputs and necessary services, then verify the selected client’s effective boundary on the intended host. Existing cloud inference can remain in place.
Diagnose without relaxing protection: use enforcing, deny-and-record diagnostics where supported. The MXC repository warns that its audit mode disables sandbox security; an access report from a permissive run is not evidence that access was blocked.
Evaluate local inference separately: confirm the model distribution, license, runtime and memory configuration. Compare representative tasks under the same tool policy, recording task success, context size, memory, time, remote connections and costs. These are proposed checks, not tests performed for this article.
Gate expansion on required features: wait for verified preview access if local/cloud routing is essential, and confirm availability of the exact Entra, Agent 365 or Intune controls the deployment needs.
For costs, Microsoft’s zero inference charge for local model calls and GitHub’s no additional charge for local sandboxing are separate statements. Neither eliminates hardware, electricity, administration, subscriptions or remaining cloud use. Compare incremental local costs with cloud spend actually avoided at acceptable task quality; the announcements alone do not establish a break-even date.
Methodology: AI-assisted reporting and decision analysis based on Microsoft and GitHub primary sources, rechecked on October 7, 2026. No model, SDK or agent was installed or tested. Calculations use attributed vendor figures; recommendations interpret documented behavior.
