Skip to content

Microsoft Copilot Gets Permissioned Access to Windows Files as Execution Containers Ship

Microsoft Copilot gains permissioned access to local Windows files and actions on Copilot+ PCs, while Microsoft Execution Containers reach general availability.

Microsoft Copilot agents in Windows 11: a Get Started window titled Build more with AI agents, listing agent apps
Microsoft Copilot · Credit: Microsoft

Microsoft Copilot on Windows will be able to read local files and recent activity, and act on them, once a user grants permission, Microsoft said. The company frames the change as hybrid intelligence: Windows decides whether a task runs on a model on the PC or in the cloud. Copilot features built on it are expected to start rolling out on Copilot+ PCs in the coming months, and Microsoft gave no firmer date.

Microsoft describes three local capabilities for Microsoft Copilot. Context lets it understand files and recent activity. Actions cover jobs such as organizing files, assessing device diagnostics, troubleshooting and coding. Models means the assistant can use AI that runs on the PC, and fall back on the cloud when a task needs it. In the Home experience, Microsoft Copilot pulls in files a person has been working on and turns them into material ready to share. In Code, it means building native Windows apps from a single prompt. Autopilot, the persistent personal agent, gets the same local context.

The safety side shipped first. Microsoft Execution Containers, or MXC, are now generally available on Windows 11, and Microsoft says they let organizations define which files and networks an agent can reach, with the policy enforced while the agent runs. Isolation options range from process and session boundaries up to virtual machines. Microsoft lists Codex from OpenAI, GitHub Copilot, OpenClaw, Replit, LM Studio, NVIDIA OpenShell and Unsloth AI as agents that already support MXC, with Anthropic's Claude Code, Perplexity, Manus, Box and others to follow. A personal agent from Meta called Muse for Windows is also due as a native app with MXC built in.

The local-model half is aimed at cost as much as privacy. Microsoft says it has shrunk its in-house MAI coding model by nearly 80% with 3-bit precision while keeping a 256K context window, and that it plans to run it on RTX Spark machines alongside DeepSeek V4 Flash and an upcoming NVIDIA Nemotron model. GitHub's HydraFusion router, which sends each task to a suitable model, is due in the GitHub Copilot app, Copilot CLI and Visual Studio Code in experimental preview later in October.

Microsoft's wording that Microsoft Copilot acts "with your permission" is the part with the least detail. It does not say whether approval is per file, per folder or per task, or how much Copilot can change without asking again. Because containment is available now and file access for Microsoft Copilot is months away, administrators will get the policy controls before the feature they are meant to govern reaches their fleet.

Share this story

Grace Sullivan

Grace Sullivan writes for the techshooked news desk, covering breaking technology stories across the site's beats. She works to the daily news standard: lead with what happened, name the source, and separate confirmed fact from claim.