Microsoft has outlined a Windows strategy that embeds support for AI agents and local models into the operating system. The plan includes agent identities managed through Microsoft Entra ID, a Windows On-Device Agent Registry (ODR) for discovering and administering local Model Context Protocol (MCP) servers, and Microsoft Execution Containers (MXC) to isolate the tools agents invoke.
Microsoft is also developing Windows ML, a hardware-agnostic local inference runtime built on ONNX Runtime that is intended to run across CPUs, GPUs, and NPUs. Several components remain under development, and reported technical behavior—including potential ODR proxy functions—has not been fully confirmed by Microsoft; organizations should assess identity controls, MCP-server governance, and container isolation before adopting these capabilities.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft demonstrated a pre-release Surface laptop with NVIDIA GPUs running the Qwen model locally alongside GitHub Copilot at approximately 40 tokens per second.
Origin Technology researchers reported that ODR appeared to proxy communications between an MCP client and MCP server. Microsoft had not confirmed the behavior; if present, it could enable inspection of MCP payloads and detection of dangerous activity.
Microsoft presented a Windows strategy featuring Entra ID-based agent identities, agent-aware Defender capabilities, the Windows On Device Agent Registry (ODR), Microsoft Execution Containers (MXC), and the Windows ML local-model runtime. ODR and MXC were characterized as still in development with limited public implementation detail.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.