On Oct 9 OpenAI Developers announced a new Codex sandbox mode on Windows built on Microsoft Execution Containers (MXC), promising faster setup, stronger network enforcement and granular file access controls on compatible Windows 11 devices. Docs now list MXC as the recommended implementation, with elevated/unelevated as legacy fallbacks. It ships in Codex CLI 0.162.0, where features.prefer_mxc is off by default in the standalone CLI; the desktop app enables it via rollout.

Key Takeaways

  • ✓Windows sandbox implementations go from 2 to 3: mxc (recommended) / elevated (preferred fallback) / unelevated (weaker network isolation)
  • ✓MXC needs zero admin elevation, zero extra Windows accounts, zero local firewall rules; commands run as the user with per-command policy
  • ✓Minimum Codex CLI 0.162.0; features.prefer_mxc is off by default in the standalone CLI
  • ✓Enterprises can block MXC with windows.allow_mxc = false in requirements.toml
  • ✓Official post: 650+ likes, 51.8K impressions within ~1.5 hours
Codex on Windows gets a Microsoft Execution Containers (MXC) sandbox: no admin setup, no extra accounts or firewall rules, native network policy and granular file access
🖼️Official Media
Click to view high-res
🧭

Turn your technical choice into a development budget

Compare 40 dev plans & simulate token costs vs $20/mo subscriptions

🔬

In-Depth Technical Analysis

OpenAI added a third Windows sandbox implementation to Codex, built on Microsoft Execution Containers (MXC). Unlike the legacy elevated mode (admin-approved setup, dedicated sandbox users, firewall rules, ACL changes) and unelevated mode (no admin, but weaker network isolation and no denied read paths), MXC uses native Windows process isolation: commands run under the user's identity with a per-command policy, with no admin elevation, extra accounts, host permission changes or local firewall rules. It honors readable, writable and denied paths from the active permission profile and enforces network access via native policy.

Codex prefers MXC when the device and policy allow it and falls back to the configured legacy sandbox otherwise; once MXC is selected, failed commands are not retried in a legacy sandbox. Limits: managed networking requires allow_local_binding = true and drops the proxy's private-network destination checks, and leftover child processes are stopped when the foreground command exits, which matters for detached dev servers. OpenAI published no timing benchmarks.

To try it on Codex CLI 0.162.0+, run the documented probe (codex -c windows.sandbox=mxc sandbox --include-managed-config --permission-profile :workspace -- cmd.exe /d /c echo MXC_OK), then set [features] prefer_mxc = true in config.toml. Admins can enforce it in requirements.toml or block it with windows.allow_mxc = false. Requires a compatible Windows 11 device.

Action HubReady to adopt this in production?

Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.