WSL Containers now generally available on Windows
Microsoft has made WSL Containers generally available, letting developers build and run Linux containers directly on Windows through the Windows Subsystem for Linux (WSL). WSL is the Windows component that has so far been used mainly to run full Linux distributions alongside the Windows desktop.
Users get the feature by running wsl --update. The update installs a new command-line tool, wslc.exe, along with an alias called container.exe, so developers can use container commands they already know.
"WSL containers CLI: wslc.exe to directly build, run and deploy Linux containers on Windows, or use its built-in alias container.exe to run the same familiar container commands," Microsoft explained.
An API for native Windows apps
The release also includes a WSL Containers API. Windows applications can use it to start and interact with Linux containers programmatically, without the user handling the containers directly.
"Access functions to run Linux containers programmatically in your native Windows apps - unlocking scenarios like running local AI workloads or using cloud-based containerized applications locally," Microsoft noted.
The generally available version also fills several gaps from the preview period. New capabilities include:
- restarting containers
- copying files into and out of containers
- health checks
- network connect and disconnect commands
- real-time container events
- mount support
- configurable storage locations
Visibility and control for security teams
For businesses, the more important part of the release is how it ties into Microsoft's management and security tooling.
WSL Containers now integrates with Microsoft Defender for Endpoint, the company's enterprise endpoint protection product. Security teams can see process, file and network activity inside containers and link that activity back to the Windows host it runs on.
Microsoft Intune, the company's device management service, can switch WSL Containers off entirely. Administrators can also use it to limit developers to images pulled from approved container registries.
"With container registry allow lists, administrators can define approved registries and help ensure developers only pull container images from that list, that meet organizational security and compliance requirements," Microsoft noted.
Developer tooling and what comes next
Microsoft is also connecting the feature to its wider developer ecosystem. VS Code Dev Containers can use wslc as their default driver, and both Aspire and the VS Code Containers extension now support WSL Containers.
The feature users have asked for most is still missing: support in the style of Docker Compose, which lets developers define and launch multi-container setups from a single file. Microsoft says work on it has already started.
"Our aim is for wsl compose up to work with your existing compose.yaml files, unchanged," Microsoft said. "We've started on this and hope to share more soon."
The company is also working on WSL's underlying networking and on file performance across the two operating systems. According to Microsoft, WSL Containers can already be up to 2x faster when Linux environments access Windows files.
Our Take
For defenders, the Defender for Endpoint and Intune integrations are the headline here, not the new CLI. Developer workstations have long been a weak spot. Containers and Linux environments running on Windows machines can sit partly outside the view of endpoint security tools, and images pulled from arbitrary registries are a known supply chain risk. Container hosts are also a real target. We recently covered the Carbonato malware hijacking Docker hosts, and that kind of activity is easier to spot when container behaviour can be tied back to the host.
Registry allow lists through Intune give organizations a central way to decide where container images come from. This suggests Microsoft wants WSL Containers to be acceptable in managed corporate environments from the start, rather than something security teams block by default.
It is worth watching how quickly administrators adopt these controls. A built-in container runtime on Windows also gives attackers a new environment to abuse, and it remains to be seen how well the Defender telemetry holds up against real intrusions. Teams should also follow the planned wsl compose up support and keep WSL patched alongside regular Windows updates such as the recent KB5124010 preview release.
