AI how to News

Codex on Windows Gets an MXC Sandbox With No Admin Setup: Check If Your PC Supports It

Codex MXC needs a compatible Windows 11 PC. Check the required builds, run the support test and see what changes during setup.

Codex MXC needs a compatible Windows 11 PC. Check the required builds, run the support test and see what changes during setup.

0 Comments
Kapill M Malani

Kapill M Malani A die-hard Liverpool FC fan, Kapill is a big fan of Batman, Android and street Cricket. In that order, probably. Email: [email protected]

October 9, 2026Announced
Compatible Windows 11 PCsWorks on
0.162.0CLI for the test
No admin approvalMXC setup

The short version

  • On compatible Windows 11 PCs, Codex can use MXC without an admin-approved setup, separate Windows accounts or local firewall rules.
  • Windows 11 24H2 needs build 26100.9278 or later; Windows 11 25H2 needs build 26200.9278 or later.
  • Codex CLI 0.162.0 or later can test MXC for one command without changing your saved sandbox choice.
  • The desktop app prefers MXC for consumer accounts when the device supports it. Standalone CLI and enterprise users can enable that preference in configuration.

Codex on Windows has a new sandbox mode built on Microsoft Execution Containers (MXC) for compatible Windows 11 PCs. It needs no administrator-approved setup and adds neither separate Windows accounts nor local firewall rules. OpenAI offers Codex on Windows through the ChatGPT desktop app, the CLI and the IDE extension.

What is the new Codex MXC sandbox on Windows?

MXC is a native Windows process isolation option for commands Codex runs. OpenAI announced the Codex mode on October 9, 2026, citing faster setup, stronger network enforcement and finer control over file access. It requires a compatible Windows 11 device.

The sandbox applies the active file and network permissions to a command and its child processes. MXC changes how Windows enforces those boundaries; it does not give a command unrestricted access to your PC.

Does my Windows 11 PC support the Codex MXC sandbox?

Your PC needs the native MXC capability and one of the Windows 11 builds listed in the Codex Windows sandbox documentation. Microsoft introduced Process Isolation for MXC in its August 27, 2026 update.

Windows 11 builds listed for MXC

Windows 11 version Minimum build Update that introduced it
24H2 26100.9278 KB5120998, August 27, 2026
25H2 26200.9278 KB5120998, August 27, 2026

Microsoft is rolling the capability out across Windows 11 devices. A matching version and build alone cannot establish that MXC works on your PC, so Codex provides a direct test.

How do I test whether Codex MXC works on my PC?

With Codex CLI 0.162.0 or later, open PowerShell in your project directory and run these two lines in order. The test attempts MXC for one command and leaves your saved sandbox selection unchanged.

codex -c windows.sandbox=mxc sandbox --include-managed-config --permission-profile :workspace -- cmd.exe /d /c echo MXC_OK
$LASTEXITCODE

A successful test prints MXC_OK and then an exit code of 0. It checks command startup using workspace permissions and any managed requirements.

Who gets MXC automatically?

For consumer accounts, the ChatGPT desktop app prefers MXC when the device supports it. Standalone CLI users and enterprise deployments can put these lines in config.toml:

[features]
prefer_mxc = true

With that preference, Codex uses MXC when device capabilities and policy allow it. Otherwise, Codex follows its legacy sandbox selection and setup flow. An organization can block MXC by setting allow_mxc = false under [windows] in its managed requirements.toml.

How does Codex MXC compare with elevated and unelevated?

Codex lists three Windows sandbox implementations. The two legacy modes remain available when MXC cannot be selected.

Setup and isolation by sandbox mode

Implementation Setup How commands and files are isolated Network isolation
mxc No administrator approval, separate Windows accounts or local firewall rules Native process isolation with file access controlled by the permission profile MXC enforces network permissions
elevated Administrator-approved setup Dedicated lower-privilege sandbox users, filesystem permission boundaries and local policy changes; sandboxed commands run without administrator privileges Local firewall rules
unelevated Available when elevated setup is unavailable and policy permits it Restricted token based on the current user and ACL-based file boundaries; denied read paths are unsupported Environment-level offline controls, with weaker isolation than elevated

Both legacy modes use a private desktop by default for additional UI isolation.

What do MXC’s file and network controls do?

Microsoft’s October 7, 2026 MXC description says a policy can separate file locations an agent may change, locations it may only read and locations it cannot access. It can also control incoming and outgoing network connections. The policy is enforced outside the agent’s control, so code running inside the boundary cannot grant itself more access.

What can break when Codex runs commands in MXC?

Commands that leave a development server running in the background need a workflow test: remaining child processes stop when the foreground command exits. MXC also allows connections to and from services on the host’s loopback interface. Managed networking requires an effective allow_local_binding = true; proxy domain rules still apply to proxied traffic.

Choosing windows.sandbox = "mxc" explicitly fails if Windows lacks the required capability or organizational policy blocks it. That differs from a preference for MXC, which allows the legacy selection and setup flow when MXC is unavailable.

One reported failure with a locked drive

A user report on the Codex GitHub tracker, opened October 4, 2026 and labeled bug, describes MXC stopping before a command starts because an unrelated BitLocker drive is locked. The reported error is “MXC launcher: enumerate MXC volume E:\: This drive is locked by BitLocker Drive Encryption. You must unlock this drive from Control Panel. (os error -2144272384)”. Other users added matching failures to the same report. The issue was open when read on October 9, 2026.

What does removing the old sandbox change?

The codex sandbox uninstall command removes machine-wide legacy sandbox accounts and network rules. It requires administrator privileges and leaves Codex home, sandbox directories and filesystem permissions in place. Codex still uses the legacy modes as fallbacks when MXC is unavailable.

When did MXC reach Windows?

Microsoft introduced Process Isolation for MXC with KB5120998 on August 27, 2026. On October 7, 2026, Microsoft said MXC was generally available. Those are MXC milestones; OpenAI’s Codex sandbox announcement followed on October 9, 2026.

Microsoft listed these agents and frameworks as already supporting MXC:

  • GitHub Copilot
  • OpenClaw
  • OpenAI Codex
  • Replit
  • LM Studio
  • Unsloth AI

Microsoft listed these as releasing support later:

  • Anthropic Claude Code
  • Box
  • Egnyte
  • Heidi Health
  • Hermes Agent by Nous Research
  • Manus
  • Perplexity
  • Raycast
  • Simular

Microsoft also described upcoming Intune policies for MXC process containers, Microsoft Entra identification of agent activity and Microsoft Agent 365 controls for managing and monitoring local agents.

What to do now
  1. Compare your Windows 11 version and build with the compatibility table, then use the test command above to check MXC on your device.
  2. If you use the standalone CLI or manage an enterprise deployment, set the MXC preference in config.toml when your policy allows it.
  3. If your workflow starts detached development servers, test how it behaves when the foreground command ends.

FAQs

Is MXC on by default in the Codex desktop app?

The ChatGPT desktop app automatically prefers MXC for consumer accounts when the Windows 11 device supports it. If the device or policy does not support MXC, Codex uses its legacy sandbox selection and setup flow.

How do I turn on MXC in the standalone Codex CLI?

In config.toml, add a [features] section with prefer_mxc = true. Codex then selects MXC for Windows commands when the device and policy support it, with the legacy flow available otherwise.

How do organizations turn off Codex MXC?

In managed requirements.toml, set allow_mxc = false under [windows]. This blocks automatic selection and an explicit windows.sandbox = "mxc" setting. Existing legacy sandbox requirements continue to apply.

Does Codex MXC need administrator-approved setup?

No. On a compatible Windows 11 device, mxc isolates commands through native Windows processes. Its setup needs no administrator approval and creates neither separate Windows accounts nor local firewall rules. The legacy elevated sandbox does require administrator-approved setup.

Does the Codex MXC sandbox work on Windows 10?

The documented MXC capability and support test are for compatible Windows 11 devices. Codex can run on recent, fully updated Windows 10 devices on a best-effort basis, but that Windows 10 support does not establish MXC availability.

What does codex sandbox uninstall remove?

codex sandbox uninstall removes the machine-wide accounts and network rules used by the legacy Windows sandbox. It needs administrator privileges and preserves Codex home, sandbox directories and filesystem permissions. The legacy sandbox modes remain Codex’s fallback when MXC is unavailable.

 

Leave a Reply

Your email address will not be published. Required fields are marked *