# Microsoft's MXC provides SDKs for containing untrusted code across operating systems

_Published Friday, October 9, 2026 at 10:19 AM EDT · Security · Latest · Tier 2 — Notable_

![Policy-driven, layered isolation and containment . Contribute to microsoft/mxc development by creating an account on GitHub. — Primary](https://opengraph.githubassets.com/65d872ed487d3fb3a9c96fb626ecfabf796dd4635d65999c72f6fbbc8c9b3656/microsoft/mxc)

Microsoft's MXC repository offers a system for running untrusted code, including model output and plugins, in isolated workloads on Windows, Linux and macOS. Rust, .NET and Node SDKs let applications specify a workload command and containment rules; MXC validates the request, selects a backend and launches the workload.

The system supports filesystem permissions, outbound network controls and restrictions on clipboard, display and graphical interface access. Its containment options range from operating-system process sandboxes to virtual machines. Host filtering depends on the backend, and audit mode disables all sandbox security for the workload being analyzed.

## Sources

- [github.com](https://github.com/microsoft/mxc)

---
Canonical: https://techandbusiness.org/newswire/s84Xn-H8d33AVKOasFVi3N
Published: 2026-10-09T14:19:10.606Z
Story chronology: 2026-10-09T05:51:29.000Z
Retrieved: 2026-10-09T16:54:40.725Z
Publisher: Tech & Business (techandbusiness.org)
