# Microsoft releases MXC framework for sandboxing untrusted code across major desktop platforms
Microsoft has published MXC, an open-source system designed to run untrusted code inside policy-controlled sandboxes on Windows, Linux and macOS. The project targets applications that need to execute model-generated code, plug-ins or external tools without granting those workloads unrestricted access to the host computer.
MXC presents one containment model over several platform-specific backends. According to the project's documentation available on the event date, those backends range from operating-system process sandboxes to full virtual machines. An application sends a container-creation request; MXC validates it, chooses an appropriate backend and launches the workload with the requested restrictions.
That abstraction is intended to reduce the amount of platform-specific isolation logic application developers must maintain. Microsoft provides typed software development kits for Rust, .NET and Node.js. The Node and .NET packages include native runtime assets, while the Rust package builds the engine, SDK and selected backends into the consuming application. Developers who cannot embed an SDK can instead invoke platform-specific executor programs using requests expressed in MXC's stable JSON schema.
The repository emphasizes that sandbox policies will often need tuning. Applications commonly encounter denied file or capability access when they are first placed inside a restricted environment. MXC includes diagnostic paths to help policy authors identify those failures, but its documentation attaches a prominent warning to audit mode: enabling that mode turns off sandbox protection and must not be used with genuinely untrusted code. Audit output is meant to help build a policy for a workload that is already trusted.
For safer troubleshooting, the project also documents deny-and-record diagnostics that preserve containment while logging blocked operations. The distinction matters because a debugging feature that silently removes isolation would defeat the main security purpose of the framework if used against unknown model output or a third-party plug-in.
MXC also describes limited diagnostic telemetry in official Microsoft builds. Telemetry is disabled unless several conditions are met, including an opt-in for the individual run, user consent on Windows, compatible administrative policy and an application setting that enables it. Administrators may block telemetry but cannot provide consent on a user's behalf. Locally compiled open-source builds are not configured to send telemetry to Microsoft, and telemetry does not operate on non-Windows systems.
The project is distributed as a component that developers add to their own applications rather than as a standalone hosted execution service. That design makes MXC relevant to desktop and server software that increasingly needs to handle generated or extensible code, while leaving the application owner responsible for selecting backends and defining policies appropriate to each workload.



