Mxc:Microsoft Execution Containers ver.1.0.0
## Japanese Translation:
Microsoft Execution Containers (MXC) は、人間の活動と自動化された活動を Microsoft Entra 統合を通じて区別しつつ、AI エージェントのアクセスを特定のファイル、ネットワーク、アプリケーションに制限するコンテナ層として一般利用可能となりました。これにより、従業員の実績を阻害することなく、AI モデルが試みようとしない場合でも未承認のアクションを防ぐことができます。開発者は、Windows、macOS、または Linux 上の適切なバックエンドにマッピングされる統一された JSON スキーマでリソース要件を宣言します。MXC は 3 つのコンテナレベルを提供しています:プロセスコンテナ(Windows 11、macOS、Linux)、セッションコンテナ(Windows 11 限定)、WSLc コンテナ(Windows 11 限定);MicroVMs は高リスクワークロード向けのハードウェア強制型の隔離を提供し、現在 Windows 11 と Linux では実験的段階にあります。組織ポリシーは近日中に Microsoft Intune を通じて管理され、Windows 11 におけるエージェント作成リクエストとリソース境界を制御します。3 つの動作モードが利用可能です:強制(未承認アクセスをブロック)、学習(拒否されたアクセスをブロックおよび記録して診断用として使用)、許可(操作を許可しつつ拒否されたアクセスを記録)。GitHub Copilot、OpenAI Codex、Replit、LM Studio、Unsloth AI などの主要な AI プラットフォームが MXC をサポートしており、Anthropic Claude Code も próximamente サポート予定です。NVIDIA は OpenShell を統合し、ファイルアクセス、推論サービス、ネットワーク制御、認証情報管理、OCSF オーディティングに対するポリシー制御を提供しています。エージェントレベルの帰属可能性により、管理者はユーザーまたはデバイスのコンテキストだけに頼らず、特定のエージェントやグループにポリシーを適用できるようになり、監査性の向上と侵害されたエージェントへの直接的なターゲティングが可能となります。この変化は、開発者にこれらの新しい境界内で安全に動作するアプリケーションを設計することを促し、MXC プロセスコンテナが Windows でアクティビティレポートを生成して最小権限ポリシーの策定を支援できるようにしています。
## Text to translate:
Microsoft Execution Containers (MXC) are now generally available as a containment layer that limits AI agents' access to specific files, networks, and applications while keeping human activity distinct from automated activity via Microsoft Entra integration. This prevents unauthorized actions—even if an AI model attempts them—without blocking employee productivity. Developers declare resource needs in a unified JSON schema that maps to appropriate backends on Windows, macOS, or Linux. MXC offers three containment levels: Process containers (Windows 11, macOS, Linux), Session containers (Windows 11 only), and WSLc containers (Windows 11 only); MicroVMs provide hardware-enforced isolation for high-risk workloads and are currently experimental on Windows 11 and Linux. Organizational policies will soon be managed via Microsoft Intune to control agent creation requests and resource boundaries on Windows 11. Three operating modes are available: Enforcement (blocks ungranted access), Learning (blocks and records denied access for diagnostics), and Permissive (allows operation while recording denied access). Leading AI platforms such as GitHub Copilot, OpenAI Codex, Replit, LM Studio, and Unsloth AI now support MXC, with upcoming support from Anthropic Claude Code; NVIDIA has integrated OpenShell to provide policy controls for file access, inference services, network controls, credential management, and OCSF auditing. Agent-level attribution enables administrators to apply policies to specific agents or groups rather than relying solely on user or device context, improving auditability and allowing teams to target compromised agents directly. This shift encourages developers to design applications that operate securely within these new boundaries, with MXC process containers able to generate activity reports on Windows to help craft least-privilege policies.