Microsoft has brought Azure Container Apps Express to general availability, a deployment model that eliminates environment provisioning steps and replaces most configuration choices with preset defaults. The company shipped Express alongside Azure Container Apps Sandboxes, the isolated compute foundation that powers it. The combination lets developers deploy container images with just a region selection and minimal app configuration, while the platform handles compute provisioning, ingress setup, and scaling automatically. Apps run on consumption-based CPU with billing calculated per second, drop to zero when not in use, and carry no charges for environment setup.

Express is built entirely on Container Apps Sandboxes, a platform component that provisions from prewarmed resource pools for subsecond startup times. Each workload runs inside its own hardware-isolated microVM boundary, with the system capable of bursting to thousands of concurrent sandboxes. The sandboxes support suspend and resume functionality, capturing complete state including memory and disk contents, with restore times under one second. Developers can use Sandboxes directly rather than through the Express layer, an approach Microsoft targets at agent platforms and secure code-execution services. The top-level resource is Microsoft.App/SandboxGroups, functioning as a management boundary for sandboxes that share configuration, similar to a Container Apps environment. Reddit users suggested the primitive had been running core Azure services, including Foundry Hosted Agents, well before the public announcement. One commenter wrote their team uses them for Python sandboxes within a customer-facing agent framework, while another described deploying them for clients through Bicep templates by simply pointing at an image.

Microsoft positions Express as developer-first and agent-first, making the second designation explicit in its description. The company states that AI-assisted workflows can create and update applications far faster than manual infrastructure configuration allows. Express delivers a focused subset of Container Apps capabilities, including scale to zero, multiple replicas, HTTP ingress on a Microsoft-managed domain, environment variables, manual secrets, IP restrictions, log streaming, and autoscaling based on HTTP, CPU, or memory rules. The service excludes custom domains, zone redundancy, Key Vault secret references, Easy Auth, OpenTelemetry, Dapr, jobs, workload profiles, GPU workloads, multiple revisions with traffic splitting, and system-assigned managed identities. Service discovery is absent, requiring apps to communicate through their public URLs, with ingress limited to HTTP only. Microsoft's documentation advises teams to use a standard environment when they need greater control over networking, GPU compute, advanced configuration options, or environment-level capabilities.

The technology addresses a specific infrastructure challenge: providing agents with isolated environments that cost nothing during idle periods and return in under a second. Google Kubernetes Engine ships a comparable pairing with Pod snapshots that checkpoint CPU and GPU memory through gVisor, combined with GKE Agent Sandbox for running untrusted agent code. Microsoft's approach pairs microVM isolation with snapshot-based suspend and resume aimed at the same workload types. At general availability, Express reaches more than 40 Azure regions, covering almost every public region where Container Apps is offered. Microsoft reports that thousands of Express apps were created during public preview, with customer feedback shaping release priorities. Teams running standard environments can migrate through archive and restore, a process Microsoft says preserves app and environment configuration, takes about 15 minutes, and doesn't change the consumption-free grant. Express requires a Microsoft Entra ID-backed account, with personal Microsoft accounts unsupported, and management happens through specialist interfaces at containerapps.azure.com and sandboxes.azure.com rather than the standard Azure portal. The platform's focus on AI agents and rapid deployment reflects a broader shift toward compute models optimized for intermittent workloads, though teams needing enterprise features like custom domains or Key Vault integration face a choice between convenience and capability.