Microsoft has made Azure Container Apps Express generally available alongside the sandbox layer beneath it. Express takes a container image and basic configuration, then handles compute, ingress and scaling without requiring developers to provision a full Container Apps environment.

The service runs on prewarmed, hardware-isolated microVM sandboxes that Microsoft says can start in under a second and scale to thousands of concurrent instances. Workloads use consumption CPU, are billed by the second and can scale to zero when idle. Developers can also use the sandbox primitive directly for agent platforms or services that execute untrusted code.

Express supports HTTP ingress on a Microsoft-managed domain, environment variables, manual secrets, multiple replicas, log streaming and autoscaling based on HTTP traffic, CPU or memory. It is available in more than 40 Azure regions and requires a Microsoft Entra ID-backed account.

The simplified setup has important limits. Express does not support custom domains, zone redundancy, GPU workloads, Key Vault secret references, OpenTelemetry, Dapr, jobs, traffic splitting or system-assigned managed identities. Service discovery is also absent, so applications communicate through public URLs. Microsoft recommends a standard Container Apps environment when a workload needs those networking, identity or resilience controls.