Sealzi / JournalStoriesAboutWhat's Vauz? Support

Microsoft wants Copilot doing things on your PC. Its announcement never mentions your passwords.

All stories ↗

On October 7, Microsoft announced that Windows is now “the home for hybrid intelligence”. Translated from keynote: AI agents that run on your own PC when they can and in Microsoft’s cloud when they can’t (hello, privacy 🙂). The headline feature is Copilot moving in properly. In the words of Windows boss Pavan Davuluri’s announcement , “With your permission, Copilot can understand relevant content on your PC, including files and recent activity”, and “Copilot can take action on your behalf across Windows”. It starts rolling out on Copilot+ PCs “in the coming months”, “with you in control”

We read both of Microsoft’s posts from that day, start to finish. The word “password” isn’t in either. Neither is “sign-in”, and neither is “browser”. An assistant that reads your files and does things on your computer, announced without one sentence about the logins sitting on that computer. That sounds interesting 🫥

What did Microsoft actually announce?

Two things matter here. The first is Copilot itself: on Copilot+ PCs it gets local context (your files, your recent activity), local AI models, and “PC actions”. The examples Microsoft gives are tame on purpose: organizing files, assessing device diagnostics, troubleshooting issues. Nobody demos “and then it logged into your bank”

The second is Microsoft Execution Containers , MXC for short, which went from preview to generally available on Windows 11. MXC is a box for agents. Microsoft calls it “a policy-driven execution layer for untrusted code or dynamically generated workloads”, which is a polite way of saying “AI that does things we can’t predict”. The box has rules for which processes the agent can run, which files it can touch, which networks it can reach, and what it can do with the user interface. Everything else is off limits “unless access has been granted”, and the rules sit outside the agent, so the agent can’t rewrite its own leash. GitHub Copilot, OpenAI’s Codex, OpenClaw and Replit already support it, with more promised

To be fair, that’s a sensible design, and better than an agent that simply runs as you. But look at who opts in. Agent developers add MXC support if they choose to. Company IT teams will “soon” be able to set their own rules for these boxes through Intune, Microsoft’s tool for managing work PCs. The part that tells Windows which agent did what, as opposed to which human, is “coming soon” too. And Davuluri’s post never says whether Copilot’s own PC actions run inside one of these boxes 🤷‍♂️

What an MXC policy can grant or deny

PolicyProcesses
PolicyFile system
PolicyNetwork
PolicyUser interface

Not on the list

Your saved loginsCovered only as files
Signed-in sessionsCovered only as files
A password dialogCovered only as screen
Copilot's own PC actionsNot stated
Microsoft Execution Containers let an agent's developer, and later your IT department, decide which processes, files, network connections and parts of the screen an agent may touch. Your saved logins and the sessions already signed in on your PC aren't a category of their own, so they're protected only as far as the files and screen around them are.

Why the missing word matters

Your PC is where your logins live. Whatever browser you use keeps the sessions for every site you’re signed in to, so you don’t have to log in again every morning. Plenty of people keep passwords in the browser itself. And if you’ve ever switched password tools, there may be an export sitting in Downloads (a plain spreadsheet with every password in it, readable by anything that can read a file)

An agent on your PC is different from an agent in the cloud, which we picked apart with OpenAI’s dots last week. A dot signs in from OpenAI’s computer, so OpenAI has to be handed your password. Copilot on your PC doesn’t need handing anything. It’s already sitting next to everything you’re signed in to. That’s the whole point of “local context”, and it’s also the whole problem

MXC’s categories don’t have a slot for “logins”. Your saved passwords and signed-in sessions are protected exactly as far as the files and screen around them are, which depends on whoever wrote the policy remembering they’re there. And “with your permission” covers the agent’s job, not each thing it touches along the way. You say yes to “tidy up my Downloads folder”. Did you also mean “open the spreadsheet called passwords.csv”? 🙄

Then there’s the company’s form. The last time Microsoft announced an AI feature that watched what you do on your PC, it was Recall. Within weeks Davuluri himself was posting the rework : make it opt-in, require Windows Hello to turn it on, and keep snapshots encrypted until you authenticate. Then Microsoft pulled Recall from the launch it was supposed to ship with, and then delayed the preview again, to December. So Microsoft now says “with you in control”. We’ll see about that 🫪

The test we keep coming back to

When an OpenAI agent went round the blocks on a Medicare portal, the lesson was simple. A “no” enforced by something the agent can reach isn’t a no. The same test works for Copilot, or any agent you let loose on your desktop: for each check that stands between it and your passwords, could the agent answer that check itself?

A browser that fills passwords automatically doesn’t ask at all. A pop-up with an Allow button asks, but an agent that can use your screen can press buttons, which is literally what “PC actions” means. Microsoft’s own containers list the user interface as something an agent can be granted. Once granted, a dialog is just another thing to click 👽

A check an agent can’t answer is one that needs something the agent doesn’t have. Your finger on a sensor. A secret that lives in your head and nowhere on the machine

Before Copilot gets its PC actions

As of October 11, none of this is switched on yet, so you have a few months to tidy up. All of it applies to any agent you install, not just Microsoft’s

Find the password exports and delete them. Search your PC for files with “password” or “export” in the name, and look in Downloads for spreadsheets you don’t recognise. If you exported passwords to move them somewhere, they’re moved. Delete the file, then empty the Recycle Bin

Give permission per job, not per folder. When Copilot asks, read what it’s asking for. “Look at this file” is a different request from “access to Documents”

Keep agents out of the browser you bank in. If you want an agent to do web errands, give it a separate browser profile that isn’t signed in to your email or your bank. Your inbox resets every other password you have, so it’s the one login no agent needs

Know your sessions. For the accounts that matter, find the “sign out of all devices” button now, while nothing is wrong. We saw what a stolen session is worth when a malicious browser extension forwarded live ones to someone else’s servers

Never type a password, or a password manager’s unlock secret, into a chat with an assistant. Anything in the conversation is something the assistant has

Where Vauz draws the line

Vauz  won’t release a login until you approve that site, in a prompt from the Vauz app that names it. The prompt runs outside the browser, so no web page can reach it, however clever the page is. An agent that can drive your desktop is a harder case

If the only thing standing in the way is the Allow/Deny dialog, an agent with access to your screen can press it. A click can be faked. A fingerprint can’t. So Vauz asks for something stronger first, whenever it has something stronger to ask for. On a Mac with Touch ID, that’s your fingerprint. Otherwise, if you’ve set a V-Key, it’s your V-Key. The plain dialog only appears when you’ve set up neither. On Windows today, the V-Key is what turns a click into a real check, so if Copilot is coming to your PC, set one up in Vauz. The next major version of Vauz adds Windows Hello, so on a PC with a fingerprint reader or a face-recognition camera, your finger or face will do the job Touch ID does on a Mac

An agent can’t type a V-Key it was never given. So don’t give it one

Who can get a login out of Vauz

Allow click
V-Key
FingerprintMac with Touch ID
A web page
Can't reach it
Can't reach it
Can't reach it
An agent driving your desktop
Can press it
Not unless you told it
No finger
You
Yes
Yes
Yes

Set a V-Key, or use Touch ID on a Mac, and the agent's one way through is gone

Vauz asks before a login leaves the vault, in a prompt from the Vauz app rather than the browser. A web page can't reach that prompt at all. An agent that can drive your desktop can press a plain Allow button, but it can't type a V-Key it was never given or put a finger on the sensor, so on Windows the V-Key is what turns a click into a check.

That’s also why Vauz is no use for letting an agent sign in to things while you’re away. A step that needs a person needs the person. We wrote about the other side of that trade when Apple’s Passwords app started changing passwords for you, and we haven’t changed our minds

What to watch

Microsoft’s posts promise “permission”, “you in control” and a way to tell agent activity from yours “coming soon”. Those are promises about behaviour, from a company that announced Recall first and fixed it after. So watch for the boring details as Copilot’s PC actions roll out: whether Copilot itself runs inside MXC, whether it can drive your browser, what one permission actually covers, and whether anyone at Microsoft writes the word “password” in the documentation

Until then, assume anything that can click on your PC can click Allow

A check an agent can't fake

Your logins leave Vauz only after you approve that site, in a prompt from the Vauz app.

No web page can reach that prompt. Set a V-Key and a click on its own isn't enough either. The free plan stays completely free for life, with Plus and Premium available when you need more!

Use Vauz completely free — for, like, ever
© 2026 Sealzi. Where privacy matters.Sealzi.com ↗Vauz ↗RSS