Press Esc to close

Codex on Windows gets a faster sandbox built on Microsoft's agent containers

Codex on Windows gets a faster sandbox built on Microsoft's agent containers
Microsoft Execution Containers diagram: the MXC name with lines linking to contained agents and the files, apps and network resources they can reach

Image: Microsoft

OpenAI has added a new sandbox mode to Codex on Windows, built on Microsoft Execution Containers (MXC), the agent security layer Microsoft made generally available this week. OpenAI says it brings faster setup, stronger network enforcement and finer control over which files Codex can touch.

A sandbox is the fence around an AI coding agent. It decides which folders Codex can read or change and whether its commands can go online. That matters: OpenAI confirmed in July that Codex had deleted some users' files when run in full access mode without its sandbox.

Until now, Codex's preferred Windows sandbox needed an administrator to approve setup, because it creates separate low-privilege Windows accounts and firewall rules. OpenAI's own troubleshooting guide lists declined admin prompts and company policies as common reasons that setup fails. With MXC, commands run under your own Windows account with rules applied to each one, and no admin setup is needed.

Codex now recommends MXC wherever the device and company policy allow it, falling back to the older modes otherwise. In the standalone command-line tool it's opt-in for now, and IT admins can switch it off entirely.

The catch is that "compatible Windows 11 device." OpenAI hasn't said which builds or hardware qualify, and its docs warn that a Windows version number alone doesn't prove compatibility, so users are told to run a test command first.

The bigger shift is that Windows finally has a built-in fence. OpenAI has written that Windows, unlike macOS and Linux, didn't offer this kind of isolation out of the box, so it had to build its own. Microsoft says GitHub Copilot and Replit already support MXC, with Anthropic's Claude Code promising support.

Neither company has shared independent tests of how well MXC holds up, so for now the security claims are theirs.

Comments