Azure ACA Sandboxes secure microVM hosting for agent orchestration with egress proxy logging and lifecycle control
Key insights
ACA Sandboxes are a managed Azure Container Apps resource that hosts agents in isolated microVMs. They provide a secure environment to run AI-generated code and untrusted workloads without exposing the rest of your system.
Each sandbox runs in its own microVM with hardware-level separation from the host and other sandboxes. This strong isolation reduces the blast radius if code misbehaves.
Sandboxes support suspend/resume and memory-plus-disk snapshots so agents can pause and continue with preserved context. That lets long-running workflows keep state without restarting from scratch.
Built-in egress policies, host allowlists, and credential controls limit outbound access and injected secrets. Teams can enforce where sandboxes connect and which credentials they receive.
They start in seconds, accept OCI container images, and integrate with CLI, SDK, REST APIs, and the portal. Sandboxes also support persistent storage and virtual network integration for private access and compliance needs.
Common uses include running AI agents, safely executing external tools, and building snapshot-driven workflows. Developers get a lightweight, secure execution primitive for orchestration, testing, and automation.