Windows Defender Sandbox


So, i guess the general consensus is this is not currently working? There is simply no functional Windows Defender Interface within the Windows Sandbox.
 

My Computer

System One

  • OS
    Windows 11 Pro
So, i guess the general consensus is this is not currently working? There is simply no functional Windows Defender Interface within the Windows Sandbox.
Gee. I wish MS would say something about this. It's sooo important.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Nobody here in the forum seems to know either.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
You are better off using a VM if that is your concern during testing.
For now, it is just not available and you are right, there seems to be no documentation on that.
Sandbox itself, in the end, uses Windows' API on the host, so everything that goes on inside the Sandbox is still protected by the Defender instance running inside the host.
 

My Computers

System One System Two

  • OS
    Win11 All /Debian/Arch
    Computer type
    Laptop
    Manufacturer/Model
    ASUSTeK COMPUTER INC. TUF Gaming FX705GM
    CPU
    2.20 gigahertz Intel i7-8750H Hyper-threaded 12 cores
    Motherboard
    ASUSTeK COMPUTER INC. FX705GM 1.0
    Memory
    24428 Megabytes
    Graphics Card(s)
    Intel(R) UHD Graphics 630 / NVIDIA GeForce GTX 1060
    Sound Card
    Intel(R) Display Audio / Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (17.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9
    Hard Drives
    2 SSD SATA/NVM Express 1.3
    WDS500G2B0A-00SM50 500.1 GB
    WDCSDAPNUW-1002 256 GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & ADSL Bouygues -fr
    Browser
    Edge Canary- Firefox Nightly
    Antivirus
    Windows Defender
    Other Info
    VMs of Windows 11 stable/Beta/Dev/Canary
    VM of XeroLinux- Arch based & Debian 12
  • Operating System
    Windows 11 Insider Canary
    Computer type
    Laptop
    Manufacturer/Model
    ASUS X751BP
    CPU
    AMD Dual Core A6-9220
    Motherboard
    ASUS
    Memory
    8 GB
    Graphics card(s)
    AMD Radeon R5 M420
    Sound Card
    Realtek
    Monitor(s) Displays
    17.3
    Screen Resolution
    1600X900 16:9
    Hard Drives
    1TB 5400RPM
You are better off using a VM if that is your concern during testing.
For now, it is just not available and you are right, there seems to be no documentation on that.
Sandbox itself, in the end, uses Windows' API on the host, so everything that goes on inside the Sandbox is still protected by the Defender instance running inside the host.
Thanks a lot.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
  • Like
Reactions: OAT
You are better off using a VM if that is your concern during testing.
For now, it is just not available and you are right, there seems to be no documentation on that.
Sandbox itself, in the end, uses Windows' API on the host, so everything that goes on inside the Sandbox is still protected by the Defender instance running inside the host.
These days running sandbox I can't see what this brings to the table any more -- most modern computers -- even a few years old would be far better off running a full blown VM.

If you want to run Linux or Android without using a VM the WSL for Linux or Android on Windows in any case is a far better option than running a sandbox -- note that a lot of Linuxprograms that run with a linux GUI will run on WSL without installing the "Native distro" too. The WSL has improved by loads recently too.

Cheers
jimbo
 

My Computer

System One

  • OS
    Windows XP,7,10,11 Linux Arch Linux
    Computer type
    PC/Desktop
    CPU
    2 X Intel i7
Firstly, this thread is using confusing terminology.

Windows Sandbox refers to running a Windows operating system in a virtualised environment where it is isolated from main OS to prevent cross infections.



Windows Defender Sandbox is really a slang term. Thisz is why people may think it no longer exists.

The correct name is Microsoft Defender Application Guard. This works at the application level sandboxing an application inside a virtualised environment.

1686483665905.png

It requires the type 1 hypervisor environment to be switched on.

The app is in effect sort of a (partial) copy running in a container and e.g. if office was being used and a document has malicious macros, the main installation of office os protected.


However, turning on the hypervisor by default can have performance issues with other 3rd party apps e.g. some android emulators fall over if MDAG is activated.

This feature is really aimed at the corporate enterprise market.
 
Last edited:

My Computer

System One

  • OS
    Windows 10 Pro + others in VHDs
    Computer type
    Laptop
    Manufacturer/Model
    ASUS Vivobook 14
    CPU
    I7
    Motherboard
    Yep, Laptop has one.
    Memory
    16 GB
    Graphics Card(s)
    Integrated Intel Iris XE
    Sound Card
    Realtek built in
    Monitor(s) Displays
    N/A
    Screen Resolution
    1920x1080
    Hard Drives
    1 TB Optane NVME SSD, 1 TB NVME SSD
    PSU
    Yep, got one
    Case
    Yep, got one
    Cooling
    Stella Artois
    Keyboard
    Built in
    Mouse
    Bluetooth , wired
    Internet Speed
    72 Mb/s :-(
    Browser
    Edge mostly
    Antivirus
    Defender
    Other Info
    TPM 2.0
Firstly, this thread is using confusing terminology.

Windows Sandbox refers to running a Windows operating system in a virtualised environment where it is isolated from main OS to prevent cross infections.



Windows Defender Sandbox is really a slang term. Thisz is why people may think it no longer exists.

The correct name is Microsoft Defender Application Guard. This works at the application level sandboxing an application inside a virtualised environment.

View attachment 62074

It requires the type 1 hypervisor environment to be switched on.

The app is in effect sort of a (partial) copy running in a container and e.g. if office was being used and a document has malicious macros, the main installation of office os protected.


However, turning on the hypervisor by default can have performance issues with other 3rd party apps e.g. some android emulators fall over if MDAG is activated.

This feature is really aimed at the corporate enterprise market.
Good explanation. Thanks for the info.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Windows Defender Sandbox, referred to as WD Sandbox, is a feature Microsoft introduced to improve the security of its Windows Defender (now Microsoft Defender) antivirus service. This feature is designed to isolate antivirus processes from the rest of the system, ensuring that if the antivirus software is attacked or compromised, the rest of the system remains protected.



As for why it is off by default, it primarily relates to system resource usage and compatibility. Running WD Sandbox uses more system resources because it creates a separate, isolated environment for the Defender processes. If your system has limited resources (CPU, RAM), running WD Sandbox could potentially slow it down. Furthermore, the feature could potentially lead to compatibility issues with some systems or software.



Turning on WD Sandbox is generally safe and could provide enhanced security, especially on systems with ample resources. However, it is important to monitor your system performance after enabling it. If you notice your system slowing down or other issues arising, you may want to reconsider its use.



As to why Microsoft has not promoted or discussed the feature as much in recent years, there could be several reasons. It is possible that Microsoft has been focusing more on other features, services, or products. Additionally, since WD Sandbox is an advanced feature that can affect system performance, it may not be suitable for all users, especially those with less powerful systems or less technical knowledge.



As for the command you provided (setx /M MP_FORCE_USE_SANDBOX 1), it is a command-line instruction that you can use to enable WD Sandbox. The /M switch is used to apply the setting for the entire system, not just the current user. However, remember to open the command prompt as an administrator before running this command, or it will not work. Also, you may need to restart your computer for changes to take effect.



Ensure you understand the implications of any changes you make to your system's configuration. In this case, while the Sandbox can provide an extra layer of security, make sure your system has the resources to manage it, and watch for any possible negative impacts on performance or compatibility.
 

My Computer

System One

  • OS
    Windows 11 Pro
Windows Defender Sandbox, referred to as WD Sandbox, is a feature Microsoft introduced to improve the security of its Windows Defender (now Microsoft Defender) antivirus service. This feature is designed to isolate antivirus processes from the rest of the system, ensuring that if the antivirus software is attacked or compromised, the rest of the system remains protected.



As for why it is off by default, it primarily relates to system resource usage and compatibility. Running WD Sandbox uses more system resources because it creates a separate, isolated environment for the Defender processes. If your system has limited resources (CPU, RAM), running WD Sandbox could potentially slow it down. Furthermore, the feature could potentially lead to compatibility issues with some systems or software.



Turning on WD Sandbox is generally safe and could provide enhanced security, especially on systems with ample resources. However, it is important to monitor your system performance after enabling it. If you notice your system slowing down or other issues arising, you may want to reconsider its use.



As to why Microsoft has not promoted or discussed the feature as much in recent years, there could be several reasons. It is possible that Microsoft has been focusing more on other features, services, or products. Additionally, since WD Sandbox is an advanced feature that can affect system performance, it may not be suitable for all users, especially those with less powerful systems or less technical knowledge.



As for the command you provided (setx /M MP_FORCE_USE_SANDBOX 1), it is a command-line instruction that you can use to enable WD Sandbox. The /M switch is used to apply the setting for the entire system, not just the current user. However, remember to open the command prompt as an administrator before running this command, or it will not work. Also, you may need to restart your computer for changes to take effect.



Ensure you understand the implications of any changes you make to your system's configuration. In this case, while the Sandbox can provide an extra layer of security, make sure your system has the resources to manage it, and watch for any possible negative impacts on performance or compatibility.
Turning it on via CMD admin seems to do nothing although shows success. This on the Canary channel, Process Explorer not showing MsMpEngCP.exe. Must be dead in the water?

Application Guard applied.png
 

My Computers

System One System Two

  • OS
    Win 11 Pro & 🐥.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
    CPU
    AMD Ryzen 7 3700U with Radeon Vega Mobile Gfx
    Motherboard
    ASUSTeK COMPUTER INC. X509DA (FP5)
    Memory
    12GB
    Graphics Card(s)
    RX Vega 10 Graphics
    Monitor(s) Displays
    Generic PnP Monitor (1920x1080@60Hz)
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung SSD 970 EVO Plus 2TB NVMe 1.3
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
Turning it on via CMD admin seems to do nothing although shows success. This on the Canary channel, Process Explorer not showing MsMpEngCP.exe. Must be dead in the water?

View attachment 62794

If you're not seeing MsMpEngCP.exe after enabling the sandbox, there could be several reasons:

  • There might be a bug or compatibility issue in the Canary build you're using.
  • The sandbox feature might be disabled or not fully implemented in that build.
  • Microsoft might have made changes to how the sandbox feature works, and the new implementation doesn't use the MsMpEngCP.exe process.
I would recommend reaching out to Microsoft Support or using the Feedback Hub to report the issue and get more up-to-date assistance.
 

My Computer

System One

  • OS
    Windows 11 Pro
If you're not seeing MsMpEngCP.exe after enabling the sandbox, there could be several reasons:

  • There might be a bug or compatibility issue in the Canary build you're using.
  • The sandbox feature might be disabled or not fully implemented in that build.
  • Microsoft might have made changes to how the sandbox feature works, and the new implementation doesn't use the MsMpEngCP.exe process.
I would recommend reaching out to Microsoft Support or using the Feedback Hub to report the issue and get more up-to-date assistance.
Thanks for the recommendation but nah thanks. Just playing around with it. I don't use Application Guard either.
 

My Computers

System One System Two

  • OS
    Win 11 Pro & 🐥.
    Computer type
    Laptop
    Manufacturer/Model
    ASUS VivoBook
    CPU
    AMD Ryzen 7 3700U with Radeon Vega Mobile Gfx
    Motherboard
    ASUSTeK COMPUTER INC. X509DA (FP5)
    Memory
    12GB
    Graphics Card(s)
    RX Vega 10 Graphics
    Monitor(s) Displays
    Generic PnP Monitor (1920x1080@60Hz)
    Screen Resolution
    1920x1080@60Hz
    Hard Drives
    Samsung SSD 970 EVO Plus 2TB NVMe 1.3
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    ACER NITRO
    CPU
    AMD Ryzen 7 5800H / 3.2 GHz
    Motherboard
    CZ Scala_CAS (FP6)
    Memory
    32 GB DDR4 SDRAM 3200 MHz
    Graphics card(s)
    NVIDIA GeForce RTX 3060 6 GB GDDR6 SDRAM
    Sound Card
    Realtek Audio. NVIDIA High Definition Audio
    Monitor(s) Displays
    15.6" LED backlight 1920 x 1080 (Full HD) 144 Hz
    Screen Resolution
    1920 x 1080 (Full HD)
    Hard Drives
    Samsung 970 Evo Plus 2TB NVMe M.2
    PSU
    180 Watt, 19.5 V
    Mouse
    Lenovo Bluetooth
    Internet Speed
    25 Mbps
    Browser
    Edge
    Antivirus
    Defender
I'm back! I have decided to leave it off because MS must have their reasons and I won't contradict that. Besides, using Insider builds as I do, may affect it in some way so I'll just leave it alone. MS will turn it back on when it's necessary.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
But MS doesn't say that. Are you sure? I'm not.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
I tried to use it as don't need a sandbox or machine very often. And it DOES NOT WORK WITH DEFENDER. Try using it and upload a virus. It doesn't pick it up. Simple. Im forced to use hyper v instead.
 

My Computer

System One

  • OS
    Windows 11 Pro
Alright. Then I'll leave it off. Or keep it on? Off or on? Off/on? I started this thread way back when and it seems no one can say anything for sure because no one knows for sure. Not even MS. I'm so sorry I brought it up. Looking for answers that are not there.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
I officially 🔐 this thread. That's it
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
I am opening this thread back up due to the fact that I have been using this feature and have not found any impact on my system what so ever.
Would like to know anyway if someone from this forum has found or knows anything else on this topic.
 

My Computer

System One

  • OS
    Win11/10 Dual Boot
    Computer type
    Laptop
    Manufacturer/Model
    HP ENVY
    CPU
    i5 Core 7200U@2.50GHz
    Motherboard
    HP 81AD (U3E1)
    Memory
    12GB
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) Intel HD Graphics 620 (HP)
    Sound Card
    Conexant ISST audio
    Monitor(s) Displays
    Generic PnP Monitor
    Screen Resolution
    1536x864 pixels
    Hard Drives
    HGST HTS721010A9E630
    Mouse
    Logitec Anywhere 2
    Internet Speed
    Good enough for me!
    Browser
    Firefox/Edge
    Antivirus
    Windows Defender and Malwarebytes
Hi,
Well good why don't tell all how exactly you used it and what apps did you use it with.

Personally I've not and never will use it because it's unnecessary.
I turn off most of defender stuff and use just the firewalls.
 

My Computer

System One

  • OS
    Win-7-10-11Pro's
    Computer type
    PC/Desktop
    Manufacturer/Model
    Acer 17" Nitro 7840sn/ 2x16gb 5600c40/ 4060/ stock 1tb-os/ 4tb sn850x
    CPU
    10900k & 9940x & 5930k
    Motherboard
    z490-Apex & x299-Apex & x99-Sabertooth
    Memory
    Trident-Z Royal 4000c16 2x16gb & Trident-Z 3600c16 4x8gb & 3200c14 4x8gb
    Graphics Card(s)
    Titan Xp & 1080ti FTW3 & evga 980ti gaming
    Sound Card
    Onboard Realtek x3
    Monitor(s) Displays
    1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24"/ 3rd LG 43" series
    Screen Resolution
    1920-1080 not sure what the t.v is besides 43" class scales from 1920-1080 perfectly
    Hard Drives
    2-WD-sn850x 4tb/ 970evo+500gb/ 980 pro 2tb.
    PSU
    1000p2 & 1200p2 & 850p2
    Case
    D450 x2 & 1 Test bench in cherry Entertainment center
    Cooling
    Custom water loops x3 with 2x mora 360mm rads only 980ti gaming air cooled
    Keyboard
    G710+x3
    Mouse
    Redragon x3
    Internet Speed
    xfinity gigabyte
    Browser
    Firefox
    Antivirus
    mbam pro
Back
Top Bottom