Windows Defender Sandbox


mecanicogolf

Well-known member
Member
VIP
Local time
2:36 AM
Posts
468
Location
Seattle
OS
Win11/10 Dual Boot
I know WD Sandbox is off by default and I don't understand why MS has been doing this for the past 2 years. Is there something wrong with enabling it? Why isn't it on by default? Is it OK to turn it on? Will it help or hinder?
I am very curious why for the past 2 years everything is quite about it. Maybe it doesn't work or do anything and that's why it's off.
Like to get your feedback on this (these) question(s).

setx /M MP_FORCE_USE_SANDBOX 1

Thanks!
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Microsoft does not enable quite a few security features by default. Many are likely overkill for home users or are not available without command line level changes or registry edits. Business environments using pro, ent or edu licensing will likely enable if they are applying OS hardening best practices through some type of management system.

IMO Microsoft will have a balanced security approach for all users with the optional hardening.
 

My Computer

System One

  • OS
    Windows 11
I know WD Sandbox is off by default and I don't understand why MS has been doing this for the past 2 years. Is there something wrong with enabling it? Why isn't it on by default? Is it OK to turn it on? Will it help or hinder?
I am very curious why for the past 2 years everything is quite about it. Maybe it doesn't work or do anything and that's why it's off.
Like to get your feedback on this (these) question(s).

setx /M MP_FORCE_USE_SANDBOX 1

Thanks!
Defender Sandbox was actually running by default when I first updated to W11, but it was disabled by a later update. This was verified by members of another forum. MS documentation on this feature is sketchy, as is often the case with Windows documentation overall. MS has probably determined that the feature is not ready for rollout, is still in development, etc. There is some security benefit to having it enabled, and there's no harm in leaving it enabled if you do not experience any performance hit.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    8GB
    Internet Speed
    45MB
    Browser
    Firefox | Chrome
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
Any more feedback on this. To this date, and with no explanation, it's still off by default.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Any more feedback on this. To this date, and with no explanation, it's still off by default.
No, except to restate my answer from above:
MS documentation on this feature is sketchy, as is often the case with Windows documentation overall. MS has probably determined that the feature is not ready for rollout, is still in development, etc.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    8GB
    Internet Speed
    45MB
    Browser
    Firefox | Chrome
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
I am running Windows Sandbox now. I followed these instructions.


Or is this the wrong sandbox?
 

My Computers

System One System Two

  • OS
    11 Pro 23H2 OS build 22631.3374
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    13Mbps
    Browser
    Brave, Edge or Firefox
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
I'm talking about Windows Defender Sandbox, not Windows Sandbox.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
So, you think it does nothing? Should I install a third-party AV that does use sandboxing to protect me?
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Last edited:

My Computer

System One

  • OS
    Windows 11 Professional
    Computer type
    PC/Desktop
    Manufacturer/Model
    Microcenter B677
    CPU
    Intel Core i5-9400
    Motherboard
    ASRock H310CM-HDV/M.2
    Memory
    32GB
    Graphics Card(s)
    Integrated Intel UHD Graphics 630
    Sound Card
    Intel Kaby Lake - High Definition Audio / cAVS (Audio, Voice, Speech) [A0]
    Monitor(s) Displays
    LG Model: GSM59F1
    Screen Resolution
    2560x1080
    Case
    Lian Li 205M
    Antivirus
    Kaspersky AV
So, you think it does nothing?
I wouldn't say that. I know of users who enable it. It's simply the fact that MS's intial documentation was very limited, and there's been no new info released in a number of years.
Should I install a third-party AV that does use sandboxing to protect me?
That's up to you. It's 6 of 1, 1/2 dozen of the other. However, you should know that Defender's sandbox is an additional self-protection measure so it can't be tampered with. If you're already using Defender you have Tamper Protection ON by default. Just stick with Defender, whether or not you enable Defender's sandbox. I hope this explanation helps your understanding. :cool:
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    8GB
    Internet Speed
    45MB
    Browser
    Firefox | Chrome
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
I understand. But I don't understand why MS made a big deal about it at the time and then has completely forgotten about it.
It seems pretty important to completely forget.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
I understand. But I don't understand why MS made a big deal about it at the time and then has completely forgotten about it.
It seems pretty important to completely forget.
It's MS. Their documentation is somewhat (?) :D fragmented and organized in ways that are not easy to find. And they have many projects that are left hanging in the air. This is well known.

A recent example is Software Restriction Policies. It was deprecated a couple or few years ago, and no longer works on the latest Windows 11 build, at least if clean installed. Try to find info on that one!
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo IdeaPad L340
    CPU
    Intel Core i3-8145U
    Memory
    8GB
    Internet Speed
    45MB
    Browser
    Firefox | Chrome
    Antivirus
    Microsoft Defender | Block unknown executables | Various ASR rules enabled
Any updates on this Defender sandbox thingy? I have it enabled and go to task manager and see it moving up and down so it must be doing something.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???
 

My Computer

System One

  • OS
    Windows 11 Pro
Any updates on this Defender sandbox thingy? I have it enabled and go to task manager and see it moving up and down so it must be doing something.

Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???

@Brink
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit 22H2 19045.4046
    Computer type
    PC/Desktop
    Manufacturer/Model
    Dell/Vostro 470 (Year 2012)
    CPU
    Intel i7-3770 @ 3.40GHz
    Memory
    8 GB
    Graphics Card(s)
    AMD 7500 Radeon HD Series
    Sound Card
    Realtek Hi-Def Audio
    Monitor(s) Displays
    Dell U2412M
    Hard Drives
    1 TB 7200 HDD
    Keyboard
    Dell/USB
    Mouse
    Dell/USB
    Internet Speed
    100/10
    Browser
    Edge
    Antivirus
    Windows Security/MalwareBytes Premium
Can anybody help here? I have ran the command to turn this on, but I can't actually find a way to run the WINDOWS DEFENDER SANDBOX?? There is obviously the standard Windows sandbox, but this doesn't run with Windows Defender in it, even with this command switched on???
Hello, and welcome. :alien:

Usually, once you have Windows Sandbox enabled like below, you should be able to open from Start menu > All apps like in the screenshot below.


start_menu_windows_sandbox-jpg.1403
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Spectre x360 2in1 14-eu0098nr (2024)
    CPU
    Intel Core Ultra 7 155H 4.8 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Graphics card(s)
    Integrated Intel Arc
    Sound Card
    Poly Studio
    Monitor(s) Displays
    14" 2.8K OLED multitouch
    Screen Resolution
    2880 x 1800
    Hard Drives
    2 TB PCIe NVMe M.2 SSD
    Internet Speed
    Intel Wi-Fi 7 BE200 (2x2) and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender and Malwarebytes Premium
Thanks for the quick reply. But isn't that just the standard Sandbox that you enable in optional features? I'm talking about the sandbox with Windows defender enabled in it? Isn't that the subject of this thread? The standard Sandbox doesn't have defender enabled in it. Even after running the setx /M MP_FORCE_USE_SANDBOX. Is it a different sandbox?
 

My Computer

System One

  • OS
    Windows 11 Pro
Once the sandboxing is enabled in Windows Sandbox, you should see a content process MsMpEngCP.exe running alongside with the antimalware service MsMpEng.exe in Windows Sandbox Task Manager to indicate Windows Defender Antivirus is running in the sandbox.

This is from 2018, so not sure if or what may have changed since then.


windows-defender-av-sandbox.png
 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gbps Download and 35 Mbps Upload
    Browser
    Google Chrome
    Antivirus
    Microsoft Defender and Malwarebytes Premium
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    HP Spectre x360 2in1 14-eu0098nr (2024)
    CPU
    Intel Core Ultra 7 155H 4.8 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Graphics card(s)
    Integrated Intel Arc
    Sound Card
    Poly Studio
    Monitor(s) Displays
    14" 2.8K OLED multitouch
    Screen Resolution
    2880 x 1800
    Hard Drives
    2 TB PCIe NVMe M.2 SSD
    Internet Speed
    Intel Wi-Fi 7 BE200 (2x2) and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Windows Defender and Malwarebytes Premium
Once the sandboxing is enabled in Windows Sandbox, you should see a content process MsMpEngCP.exe running alongside with the antimalware service MsMpEng.exe in Windows Sandbox Task Manager to indicate Windows Defender Antivirus is running in the sandbox.

This is from 2018, so not sure if or what may have changed since then.


windows-defender-av-sandbox.png
This was 5 years ago and MS has said nothing more about it? After all the fuss about Defender having a sandbox, it's hard to believe it has been dismissed and forgotten. It was on by default at one time, in the beginning, but now it just sits there in the dark. If they have it off by default, it must mean it does nothing or is completely worthless and MS has ignored everything about it. Dead end.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes

Latest Support Threads

Back
Top Bottom