Windows Defender Sandbox


mecanicogolf

Well-known member
Power User
VIP
Local time
3:06 PM
Posts
1,088
Location
Seattle
OS
Win10/11 Triple Boot Insider Release Preview and DEV channels
I know WD Sandbox is off by default and I don't understand why MS has been doing this for the past 2 years. Is there something wrong with enabling it? Why isn't it on by default? Is it OK to turn it on? Will it help or hinder?
I am very curious why for the past 2 years everything is quite about it. Maybe it doesn't work or do anything and that's why it's off.
Like to get your feedback on this (these) question(s).

setx /M MP_FORCE_USE_SANDBOX 1

Thanks!
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
Microsoft does not enable quite a few security features by default. Many are likely overkill for home users or are not available without command line level changes or registry edits. Business environments using pro, ent or edu licensing will likely enable if they are applying OS hardening best practices through some type of management system.

IMO Microsoft will have a balanced security approach for all users with the optional hardening.
 

My Computer

System One

  • OS
    Linux Mint
    Computer type
    Laptop
    Manufacturer/Model
    System76 Lemur Pro
I know WD Sandbox is off by default and I don't understand why MS has been doing this for the past 2 years. Is there something wrong with enabling it? Why isn't it on by default? Is it OK to turn it on? Will it help or hinder?
I am very curious why for the past 2 years everything is quite about it. Maybe it doesn't work or do anything and that's why it's off.
Like to get your feedback on this (these) question(s).

setx /M MP_FORCE_USE_SANDBOX 1

Thanks!
Defender Sandbox was actually running by default when I first updated to W11, but it was disabled by a later update. This was verified by members of another forum. MS documentation on this feature is sketchy, as is often the case with Windows documentation overall. MS has probably determined that the feature is not ready for rollout, is still in development, etc. There is some security benefit to having it enabled, and there's no harm in leaving it enabled if you do not experience any performance hit.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    16GB
    Hard Drives
    500 GB M2 1 TB HDD
    Internet Speed
    400 MB
    Browser
    Chrome | Edge
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
Not surprising, it may also disable if you have another EPP solution in place.
 

My Computer

System One

  • OS
    Linux Mint
    Computer type
    Laptop
    Manufacturer/Model
    System76 Lemur Pro
Any more feedback on this. To this date, and with no explanation, it's still off by default.
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
Any more feedback on this. To this date, and with no explanation, it's still off by default.
No, except to restate my answer from above:
MS documentation on this feature is sketchy, as is often the case with Windows documentation overall. MS has probably determined that the feature is not ready for rollout, is still in development, etc.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    16GB
    Hard Drives
    500 GB M2 1 TB HDD
    Internet Speed
    400 MB
    Browser
    Chrome | Edge
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
I am running Windows Sandbox now. I followed these instructions.


Or is this the wrong sandbox?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.3915
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
I'm talking about Windows Defender Sandbox, not Windows Sandbox.
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
So, you think it does nothing? Should I install a third-party AV that does use sandboxing to protect me?
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
Last edited:

My Computer

System One

  • OS
    Windows 11 Professional
    Computer type
    PC/Desktop
    Manufacturer/Model
    Microcenter B677
    CPU
    Intel Core i5-9400
    Motherboard
    ASRock H310CM-HDV/M.2
    Memory
    32GB
    Graphics Card(s)
    Integrated Intel UHD Graphics 630
    Sound Card
    Intel Kaby Lake - High Definition Audio / cAVS (Audio, Voice, Speech) [A0]
    Monitor(s) Displays
    LG Model: GSM59F1
    Screen Resolution
    2560x1080
    Case
    Lian Li 205M
    Antivirus
    Kaspersky AV
So, you think it does nothing?
I wouldn't say that. I know of users who enable it. It's simply the fact that MS's intial documentation was very limited, and there's been no new info released in a number of years.
Should I install a third-party AV that does use sandboxing to protect me?
That's up to you. It's 6 of 1, 1/2 dozen of the other. However, you should know that Defender's sandbox is an additional self-protection measure so it can't be tampered with. If you're already using Defender you have Tamper Protection ON by default. Just stick with Defender, whether or not you enable Defender's sandbox. I hope this explanation helps your understanding. :cool:
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    16GB
    Hard Drives
    500 GB M2 1 TB HDD
    Internet Speed
    400 MB
    Browser
    Chrome | Edge
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
I understand. But I don't understand why MS made a big deal about it at the time and then has completely forgotten about it.
It seems pretty important to completely forget.
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
I understand. But I don't understand why MS made a big deal about it at the time and then has completely forgotten about it.
It seems pretty important to completely forget.
It's MS. Their documentation is somewhat (?) :D fragmented and organized in ways that are not easy to find. And they have many projects that are left hanging in the air. This is well known.

A recent example is Software Restriction Policies. It was deprecated a couple or few years ago, and no longer works on the latest Windows 11 build, at least if clean installed. Try to find info on that one!
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    16GB
    Hard Drives
    500 GB M2 1 TB HDD
    Internet Speed
    400 MB
    Browser
    Chrome | Edge
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
Any updates on this Defender sandbox thingy? I have it enabled and go to task manager and see it moving up and down so it must be doing something.
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.
Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???
 

My Computer

System One

  • OS
    Windows 11 Pro
Any updates on this Defender sandbox thingy? I have it enabled and go to task manager and see it moving up and down so it must be doing something.

Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???

@Brink
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit 22H2 19045.4046
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell/Vostro 470 (Year 2012)
    CPU
    Intel i7-3770 @ 3.40GHz
    Memory
    8 GB
    Graphics Card(s)
    AMD 7500 Radeon HD Series
    Sound Card
    Realtek Hi-Def Audio
    Monitor(s) Displays
    Dell U2412M
    Hard Drives
    1 TB 7200 HDD
    Keyboard
    Dell/USB
    Mouse
    Dell/USB
    Internet Speed
    100/10
    Browser
    Edge
    Antivirus
    Windows Security/MalwareBytes Premium
Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???
Hello, and welcome. :alien:

Usually, once you have Windows Sandbox enabled like below, you should be able to open from Start menu > All apps like in the screenshot below.


start_menu_windows_sandbox-jpg.1403
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender
Thanks for the quick reply. But isn't that just the standard Sandbox that you enable in optional features? I'm talking about the sandbox with Windows defender enabled in it? Isn't that the subject of this thread? The standard Sandbox doesn't have defender enabled in it. Even after running the setx /M MP_FORCE_USE_SANDBOX. Is it a different sandbox?
 

My Computer

System One

  • OS
    Windows 11 Pro
Once the sandboxing is enabled in Windows Sandbox, you should see a content process MsMpEngCP.exe running alongside with the antimalware service MsMpEng.exe in Windows Sandbox Task Manager to indicate Windows Defender Antivirus is running in the sandbox.

This is from 2018, so not sure if or what may have changed since then.


windows-defender-av-sandbox.png
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender
Once the sandboxing is enabled in Windows Sandbox, you should see a content process MsMpEngCP.exe running alongside with the antimalware service MsMpEng.exe in Windows Sandbox Task Manager to indicate Windows Defender Antivirus is running in the sandbox.

This is from 2018, so not sure if or what may have changed since then.


windows-defender-av-sandbox.png
This was 5 years ago and MS has said nothing more about it? After all the fuss about Defender having a sandbox, it's hard to believe it has been dismissed and forgotten. It was on by default at one time, in the beginning, but now it just sits there in the dark. If they have it off by default, it must mean it does nothing or is completely worthless and MS has ignored everything about it. Dead end.
 

My Computer

System One

  • OS
    Win10/11 Triple Boot Insider Release Preview and DEV channels
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz (Unsupported for Win 11)
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    PSU
    Well...PSU you!! What's this mean?
    Case
    HP ENVY SILVER
    Cooling
    A fan.
    Keyboard
    USA
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me! Fast!
    Browser
    Edge/Waterfox
    Antivirus
    Windows Defender
    Other Info
    No 'mo.

Latest Support Threads

Back
Top Bottom