Codex on Windows gets a sandbox that needs no admin approval, and the CLI turns it on with one line
First seen on X 32 hours ago@OpenAIDevs ♥ 1,549
OpenAI's developer account said on October 9 that Codex on Windows has a new sandbox mode built on Microsoft Execution Containers (MXC), with faster setup, stronger network enforcement and finer-grained file access controls. It requires a compatible Windows 11 device. According to the docs, MXC uses native process isolation without administrator-approved setup, extra Windows accounts or local firewall rules, which the older elevated mode needed.
The ChatGPT desktop app picks MXC automatically for consumer accounts when the device supports it. For the standalone CLI or enterprise rollouts, add prefer_mxc = true under [features] in config.toml. Microsoft introduced MXC process isolation in Windows 11 24H2 (build 26100.9278) and 25H2 (build 26200.9278) and is rolling it out device by device. In Codex CLI 0.162.0 and later, the codex sandbox command can run a single command under MXC to check whether your machine supports it. Child processes stop when the foreground command exits, so the docs suggest testing workflows that rely on detached dev servers.