Microsoft made WSL Containers generally available on September 29, 2026, delivering a built-in Linux container platform for the Windows Subsystem for Linux that lets developers build images, run containers, and manage storage without requiring Docker Desktop, according to official release details.
WSL Containers Runtime Integration
The generally available release follows a public preview period launched on June 29, 2026, within WSL 2.9.3. Users can install the updated architecture simply by running wsl --update in their terminal, bypassing the previous requirement for pre-release flags. Microsoft packages the feature with both a command-line interface via wslc.exe (alongside an alias container.exe) and an official API designed for C# and C++ applications.
Since the initial preview, Microsoft has expanded the runtime toolkit with several administrative and diagnostic commands. Developers can now execute wslc container restart to reboot active instances, utilize wslc container cp for file transfers, and run wslc system info to inspect overall runtime health. Additional additions include real-time container event streams, health checks, configurable stop timeouts, and custom storage path assignments for default sessions.
Virtual Machine Architecture and Process Isolation
Unlike standard WSL implementations where client requests remain tied to the privileged wslservice.exe daemon for virtual machine management, WSL Containers introduces a distinct architectural separation. When a user initiates a session, wslservice.exe spawns a child process named wslcsession.exe that operates under the specific user’s permission level.

This lower-privilege child process handles directory sharing, network port mapping, and container creation. Microsoft structured this isolation model to reinforce security boundaries between independent development environments. Each session can encompass multiple networks, volumes, and images, with state data preserved inside a session-specific virtual hard disk typically stored at %AppData%Localwslcsessions.
Enterprise Security Controls and Device Management
For administrative oversight, Microsoft integrated direct management hooks into Microsoft Intune. Administrators can deploy device management policies to enable or disable the container runtime across corporate fleets and restrict image pulls to approved container registries.
Security monitoring is built directly into the host infrastructure. Microsoft Defender for Endpoint extends its existing WSL plugin architecture to inspect containerized workloads. The security tool surfaces process, file, and network telemetry originating inside Linux containers and correlates that activity directly with the Windows host, removing the need for separate monitoring workflows.
Developer Integration and Current Limitations
Ecosystem tool support accompanies the general availability launch. Visual Studio Code dev containers can now designate wslc as their native driver, while .NET Aspire can treat WSL containers as a primary container runtime.
Despite expanded capabilities, the platform is not a universal substitute for Docker Desktop. Compose file support remains absent, with Microsoft noting that running existing compose.yaml files natively is the top feature request for the platform. Furthermore, while Microsoft claims up to twice faster file access performance between Linux environments and Windows storage, specific benchmark conditions have not been published.