Skip to main content
CybersecurityInfrastructure

Microsoft Expands WSL with Native Linux Container Support

Developer working on Windows laptop with Linux terminal on screen.
"WSL containers CLI: wslc.exe to directly build, run and deploy Linux containers on Windows, or use its built-in alias container.exe to run the same familiar container commands," Microsoft explained.

WSL Containers: general availability and core commands

Microsoft has moved WSL Containers to general availability. Administrators and developers can install the feature by running wsl --update. The release adds a new command-line tool, wslc.exe, and ships container.exe as a built-in alias so users can issue familiar container commands on Windows.

The company described the CLI as a way "to directly build, run and deploy Linux containers on Windows," and it pairs the command surface with a WSL Containers API that lets native Windows applications launch and interact with Linux containers programmatically. Microsoft framed that API as unlocking "scenarios like running local AI workloads or using cloud-based containerized applications locally."

New operational features in the GA release

The general availability update restores and expands capabilities that were missing in preview. Microsoft said the GA release adds restarting containers, copying files in and out of containers, health checks, network connect and disconnect commands, real-time container events, mount support, and configurable storage locations. Those additions aim to bring parity with common container workflows and make containers easier to operate from a Windows host.

Microsoft also reported that WSL Containers can already deliver performance improvements when Linux environments access Windows files, noting up to 2x faster performance for that cross-OS file access.

Integration with Microsoft Defender for Endpoint and Intune

Microsoft is positioning WSL Containers to fit into enterprise security and device-management tooling. WSL Containers now integrates with Microsoft Defender for Endpoint so security teams "can see process, file, and network activity inside containers and relate it back to the Windows host." That linkage is intended to provide visibility into container activity within the same telemetry and investigation pipelines used for native Windows processes.

Device-management controls are available through Microsoft Intune. Administrators can disable WSL Containers entirely, or restrict developers to images from approved registries. As Microsoft put it, "With container registry allow lists, administrators can define approved registries and help ensure developers only pull container images from that list, that meet organizational security and compliance requirements."

Developer tooling: VS Code, extensions, and the promise of compose

Microsoft is working with the broader developer ecosystem on integrations. VS Code Dev Containers can use wslc as their default driver, and Aspire and the VS Code Containers extension now support WSL Containers. Those connections let developers keep familiar editor-driven workflows while targeting Linux containers that run on Windows.

The most requested missing feature — Docker Compose-style support — is already in development. Microsoft said, "Our aim is for wsl compose up to work with your existing compose.yaml files, unchanged." The company added that it has started work and hopes to share more soon; the new command wsl compose up is explicitly named as forthcoming.

What this means for security teams, enterprises, and developers

  • Security teams: Can use Defender for Endpoint integration to observe process, file, and network activity inside containers and correlate that telemetry with the Windows host.
  • Enterprises and IT managers: Can centrally control WSL Containers with Intune — disabling the feature or enforcing container registry allow lists and configurable storage locations to meet compliance needs.
  • Developers: Gain a native Windows CLI (wslc.exe/container.exe), VS Code driver support, and a programmatic API to launch containers from Windows apps; they should watch for wsl compose up to allow existing compose.yaml files to run unchanged.

Microsoft’s GA release frames WSL as more than a way to run Linux distributions on Windows: it is now a container host with enterprise controls, performance claims, and editor and API integrations. To try it, run wsl --update and explore wslc.exe or the container.exe alias; for many teams, the next milestone will be when wsl compose up arrives and whether it runs unmodified compose.yaml files as promised.

Source: BleepingComputer — Microsoft is rolling out Linux container support to WSL