Skip to content
Innovation & Growth

Microsoft launches Linux containers on Windows with admin controls alongside

WSL containers are now generally available. The controls that matter most are an on/off switch and an image allow list.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Microsoft launches Linux containers on Windows with admin controls alongside

AI-generated image for WebPulse. About our images

Key finding

Intune controls to check first: 2 (Source: Help Net Security (September 30, 2026))

A new door for software on every developer laptop

A container runtime on a developer's laptop is a door. Software from outside the company walks through it and runs. The question for leaders is who holds the key.

Microsoft has just made that question concrete. It announced that WSL containers are generally available. WSL is the Windows Subsystem for Linux, which runs Linux on a Windows machine. The new feature lets developers run Linux containers there. A container bundles an application with everything it needs to run.

The lesson here is that the useful part of this release is not speed or convenience. It is that Microsoft paired general availability with governance controls. It also built them on management tools many IT teams already use for WSL. The sources do not say whether the preview had similar controls. So the news is the pairing at launch, not a claim that it is a first.

What Microsoft shipped

Microsoft says people can install WSL containers by running wsl --update or by downloading a release from GitHub. The feature has two main parts.

The main interface is a command-line program named wslc.exe. Microsoft also supplies container.exe as a second name for it. That lets people used to other container tools reuse their habits.

The second part is an API. It lets native Windows applications start Linux containers from code. Microsoft cites local AI workloads as one example.

The general release builds on the preview with new lifecycle and monitoring tools. Examples include restarting a container, copying files across the boundary, health checks and a running feed of events. Developers using VS Code can pick wslc to power their dev containers. Aspire, a developer framework, can use WSL containers as its container engine.

How the controls work

Container images come from registries, which are servers that host them. Whoever controls the registry controls what code lands on the laptop. That makes the registry the point where risk enters.

Microsoft Intune, its device management product, now offers settings for this. Administrators can turn the whole WSL containers feature on or off. They can also set a registry allow list, so developers pull images only from approved sources. Microsoft says the aim is to keep images within an organization's security and compliance requirements.

2
Intune controls to check first
Source: Help Net Security (September 30, 2026)

Microsoft describes this as an extension of its Intune and Defender for Endpoint integrations for WSL, now covering container workflows. Defender's existing WSL plugin now reaches into containers. Per Microsoft, analysts can see a container's process, file and network activity and link it to the Windows host. That keeps investigations in one workflow rather than two.

What the announcement does not settle

Microsoft claims wslc can read Windows files from Linux up to twice as fast. Help Net Security points out that "up to" describes a ceiling. Microsoft gave no test conditions. Treat it as a claim to verify on your own hardware.

Up to 2x
Faster Windows file access from Linux, at most
Source: Microsoft Windows Developer blog (September 29, 2026)

The sources also leave open whether the allow list covers every path an image could take. They do not say how the settings behave on existing fleets. Those are questions for a pilot, not assumptions.

One gap is stated plainly. Compose support is missing. Microsoft calls it the top feature request. Its stated aim is for "wsl compose up" to work with current compose.yaml files without edits. Until then, teams with multi-container setups may work around it. Workarounds tend to be the places policy gets skipped.

Questions to put to your teams

Ask your endpoint team whether the WSL containers setting is decided before the update reaches developers. Ask which registries are approved, and who reviews requests to add one. Ask whether your Defender for Endpoint coverage includes the container plugin, and whether analysts have seen its output.

Ask your engineering leads which local AI workloads they plan to run in containers. The API makes that easy to build. It also means code may run in places your review process does not yet reach.

A container runtime with a switch and a guest list is a manageable tool. One without them is a blind spot. Microsoft has supplied the switch. Deciding to use it is still your job.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Microsoft.

Share this insight