The 4 best methods to enable Windows Sandbox and configure policies in Windows 11 are Optional Features, PowerShell, DISM, and Group Policy/MDM. Optional Features is best for one PC; PowerShell and DISM enable the feature for automation; Group Policy/MDM controls behavior after installation. Windows 11 Home is unsupported.
Windows Sandbox is a built-in, disposable Windows environment for testing installers, scripts, downloads, and configuration changes without keeping the session after Sandbox closes. The first three methods install the underlying optional feature. Group Policy, MDM, and .wsb files configure what the Sandbox can access; they do not replace feature installation.
Key takeaways
- Windows Sandbox is supported on Windows 11 Pro, Enterprise, Education, and supported IoT Enterprise editions, but not as a standard feature of Windows 11 Home.
- Microsoft requires compatible AMD64 or Arm64 hardware, firmware virtualization, at least 4 GB of RAM, at least 1 GB of free storage, and at least two CPU cores; Microsoft recommends 8 GB of RAM and four hyper-threaded cores.
- Optional Features is the simplest method for one computer, PowerShell is the most convenient method for repeatable scripts, and DISM is suited to command-line deployment and servicing.
- Group Policy and MDM configure networking, mapped folders, vGPU, audio, video, printer redirection, and related behavior, but they do not install Windows Sandbox by themselves.
- A network-disabled, vGPU-disabled
.wsbprofile with no mapped folders is the safer starting point for suspicious files. - Windows 11 version 24H2 has a documented limitation in which several inbox Store applications are unavailable inside Sandbox, while Windows 11 version 22H2 and later can preserve data across restarts made within a running Sandbox session.
What is Windows Sandbox and what is it used for?
Windows Sandbox is a temporary, isolated Windows desktop that uses hypervisor-based virtualization. Software, files, and configuration changes made during a session are generally discarded when the Sandbox closes. Microsoft describes the isolation model and disposable behavior in its Windows Sandbox overview.
Windows Sandbox is useful for testing an installer before running it on the host, opening a suspicious attachment, checking a script, demonstrating software, reproducing a Windows-only problem, or testing browser behavior. Windows Sandbox is not a persistent development environment, application server, durable file store, or absolute guarantee that every malicious sample is harmless.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
- SonicWall Capture Advanced Threat Protection (ATP) For TZ670 - 1 Year License (02-SSC-5035)
- Multi-Engine Sandboxing Technology: Detects and blocks zero-day threats, ransomware, and unknown malware before they enter your network.
- Real-Time Deep Memory Inspection (RTDMI): Uncovers evasive, memory-based attacks that traditional defenses miss by analyzing code behavior at runtime.
- Seamless Firewall Integration: Works in tandem with SonicWall firewalls and security services for automated breach prevention and response.
- Cloud-Based Threat Intelligence: Leverages SonicWall's global GRID network to provide continuous updates and intelligent analysis of emerging threats.
Windows Sandbox remains disposable even though Microsoft documents a persistence distinction beginning with Windows 11 version 22H2: data can survive restarts initiated inside the running Sandbox. Closing the Sandbox session still removes the environment. Do not use that restart behavior as a replacement for persistent virtual-machine storage.
Which Windows 11 editions and hardware support Windows Sandbox?
Windows Sandbox requires a supported Windows 11 edition, compatible processor architecture, firmware virtualization, adequate resources, and the optional feature itself. Microsoft’s installation requirements should be treated as the authority for supported editions, architectures, and current build-specific conditions.
| Requirement | What to check | Important qualification |
|---|---|---|
| Windows edition | Windows 11 Pro, Enterprise, Education, or supported IoT Enterprise | Windows 11 Home does not provide Windows Sandbox as a standard supported feature. |
| Architecture | Compatible AMD64 or supported Arm64 hardware | Architecture and build support must match the installed Windows release. |
| Memory | At least 4 GB of RAM | Microsoft recommends 8 GB. |
| Storage | At least 1 GB of free disk space | An SSD is preferable for startup and general responsiveness. |
| Processor | At least two CPU cores | Microsoft recommends four cores with hyper-threading. |
| Virtualization | Hardware virtualization enabled in UEFI/BIOS | Intel VT-x or AMD-V/SVM may be the relevant firmware setting. |
| Virtual machine host | Nested virtualization exposed to the Windows 11 guest | A Windows 11 VM cannot use Sandbox unless its host exposes the required virtualization extensions. |
How do you check the Windows 11 edition?
Open Settings > System > About, then inspect Windows specifications > Edition. Check the edition before troubleshooting a missing Windows Sandbox entry. Unsupported Windows 11 Home installations should not be “fixed” with registry hacks or other unsupported workarounds.
How do you check hardware virtualization?
Open Task Manager > Performance > CPU and look for Virtualization: Enabled. If virtualization is disabled, restart the computer, enter UEFI/BIOS setup, and enable the processor’s virtualization option. The label varies by manufacturer; Intel systems commonly use VT-x terminology, while AMD systems may use AMD-V or SVM.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsIf Windows 11 is itself running inside Hyper-V, VMware, VirtualBox, a cloud desktop, or another virtual platform, the host must expose nested virtualization. On a Hyper-V host, Microsoft documents these PowerShell commands:
Set-VMProcessor -VMName <VMName> -ExposeVirtualizationExtensions $true
Update-VMVersion -VMName <VMName>
Run the commands on the Hyper-V host and replace <VMName> with the actual virtual machine name. Nested virtualization support and configuration differ between hypervisors, so a guest that meets every Windows requirement can still fail if the host hides virtualization extensions.
Which of the four Windows Sandbox methods is best?
The best method depends on whether the task is a one-time installation, scripted deployment, image servicing, or centralized policy management.
| Method | Best for | Strength | Limitation |
|---|---|---|---|
| Optional Features dialog | One computer and first-time setup | Visual, simple, and difficult to mis-type | Not convenient for automation. |
| PowerShell | Administrators, scripts, and repeatable setup | Easy to automate and verify | Requires an elevated session and the exact feature name. |
| DISM | Deployment, servicing, and recovery workflows | Fits command-line and image-management processes | Less approachable and sensitive to syntax errors. |
| Group Policy or MDM | Managed fleets | Central control over Sandbox integrations and restrictions | Configures behavior; it does not install the optional feature. |
.wsb profile |
Repeatable per-session configurations | Launches a consistent test environment | It is a configuration technique, not an enablement method. |
Method 1: How do you enable Windows Sandbox from Optional Features?
The Optional Features dialog is the best method for most individual users because it provides visible confirmation that Windows is installing the correct feature.
Recommended Free Tools
- Press Windows + R.
- Enter
optionalfeaturesand press Enter. - Select Windows Sandbox.
- Select OK.
- Restart Windows if prompted.
- Open Start and search for Windows Sandbox.
The feature being installed is named Containers-DisposableClientVM. After a successful installation and restart, Windows Sandbox should appear as an application in the Start menu. If Windows Sandbox is absent from the list, the computer may not meet the edition, architecture, virtualization, or other prerequisites documented by Microsoft.
Method 2: How do you enable Windows Sandbox with PowerShell?
PowerShell is the best choice when the installation must be repeatable, scripted, remotely administered, or applied to several computers.
Rank #2
- SonicWall Capture Advanced Threat Protection (ATP) For TZ570 - 1 Year License (02-SSC-5083)
- Multi-Engine Sandboxing Technology: Detects and blocks zero-day threats, ransomware, and unknown malware before they enter your network.
- Real-Time Deep Memory Inspection (RTDMI): Uncovers evasive, memory-based attacks that traditional defenses miss by analyzing code behavior at runtime.
- Seamless Firewall Integration: Works in tandem with SonicWall firewalls and security services for automated breach prevention and response.
- Cloud-Based Threat Intelligence: Leverages SonicWall's global GRID network to provide continuous updates and intelligent analysis of emerging threats.
Open PowerShell as Administrator or open an elevated Windows Terminal, then run:
Enable-WindowsOptionalFeature `
-FeatureName "Containers-DisposableClientVM" `
-All `
-Online
The equivalent one-line command is:
Enable-WindowsOptionalFeature -FeatureName "Containers-DisposableClientVM" -All -Online
Restart if PowerShell requests it:
Restart-Computer
After Windows restarts, verify the feature state:
Get-WindowsOptionalFeature -Online `
-FeatureName "Containers-DisposableClientVM"
The desired result includes:
State : Enabled
PowerShell errors can result from a non-administrator terminal, an unsupported edition, disabled firmware virtualization, a damaged component store, missing nested virtualization, or an organizational policy that blocks the feature. The command cannot overcome an unsupported edition or a host hypervisor that does not expose nested virtualization.
Free tools Windows power users keep installed
One-click scans. No signup required.
Method 3: How do you enable Windows Sandbox with DISM?
DISM is useful for deployment scripts, elevated Command Prompt or Terminal workflows, recovery procedures, and administrators who standardize on Windows servicing tools.
Open Command Prompt, Windows Terminal, or PowerShell as Administrator and run:
DISM /Online /Enable-Feature /FeatureName:Containers-DisposableClientVM /All
Restart Windows after the command completes:
shutdown /r /t 0
Verify the feature with:
DISM /Online /Get-FeatureInfo /FeatureName:Containers-DisposableClientVM
Look for an enabled feature state. The /Online switch targets the currently running Windows installation. An offline mounted Windows image requires a different servicing workflow and should not be treated as interchangeable with the command above.
What should you do if DISM reports component-store errors?
Component-store repair can help when Windows servicing files are damaged, but repair commands are not guaranteed to fix virtualization, policy, driver, or nested-virtualization problems. Run these general Windows health checks from an elevated terminal:
DISM /Online /Cleanup-Image /CheckHealth
DISM /Online /Cleanup-Image /ScanHealth
DISM /Online /Cleanup-Image /RestoreHealth
sfc /scannow
Restart after repairs, try the feature-enable command again, and continue checking edition, firmware virtualization, host virtualization, and policy restrictions if the failure remains.
Method 4: How do Group Policy and MDM configure Windows Sandbox?
Group Policy and MDM are the right method for controlling Sandbox behavior across managed Windows 11 devices, but policy configuration does not install the Containers-DisposableClientVM optional feature by itself.
In Local Group Policy Editor or a domain policy editor, the relevant path is:
Computer Configuration
> Administrative Templates
> Windows Components
> Windows Sandbox
Microsoft maps the Windows Sandbox policies to:
HKLMSOFTWAREPoliciesMicrosoftWindowsSandbox
For MDM and Intune-style administration, use Microsoft’s Windows Sandbox Policy CSP documentation. Policy names, supported editions, and minimum Windows versions vary, and installed ADMX templates can affect which Group Policy settings are visible.
Which Windows Sandbox policies should you configure?
| Policy | What it controls | Safer default |
|---|---|---|
| Allow networking | Whether the Sandbox receives network access | Disable when testing suspicious files does not require internet access. |
| Allow mapped folders | Whether host folders can be exposed inside Sandbox | Disable unless file exchange is required. |
| Allow writing to mapped folders | Whether Sandbox processes can modify mapped host folders | Disable; Microsoft lists this policy for Windows 11 version 24H2 and later. |
| Allow vGPU sharing | Whether Sandbox can use virtualized GPU access | Disable when graphics performance is not required because vGPU can increase attack surface. |
| Allow printer redirection | Whether host printers are shared with Sandbox | Disable unless printing is part of the test. |
| Allow audio input | Whether Sandbox can access host audio input | Disable unless an audio test requires it. |
| Allow video input | Whether Sandbox can access host camera or video input | Disable unless a camera or video test requires it. |
Networking is convenient for downloading test dependencies, but network access can allow suspicious software to contact external systems or attempt unwanted activity. Mapped folders create a deliberate path from the host into the isolated environment. Avoid mapping Documents, Desktop, password stores, browser profiles, cloud-sync roots, source repositories containing secrets, SSH keys, or cryptocurrency wallets.
Read-only mappings reduce the chance that a process will modify host files, but read-only does not mean that sensitive data is safe to expose. A process inside Sandbox may still be able to read everything in a mapped folder. A locally created .wsb preference should not be assumed to override centrally enforced Group Policy or MDM settings.
Microsoft notes that vGPU policy changes require Windows Sandbox to be restarted before the change takes effect. Restart Sandbox after changing vGPU policy, and reboot Windows after feature installation or when policy processing remains stale.
How do you create a safer Windows Sandbox .wsb profile?
A .wsb file is an XML-based per-session configuration. It can control networking, vGPU, mapped folders, logon commands, and protected-client behavior. A .wsb file can be opened by double-clicking it or launched from the command line, as documented in Microsoft’s Windows Sandbox configuration-file reference.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Minimal .wsb file
Create a file named BasicSandbox.wsb containing:
<Configuration>
</Configuration>
When saving with Notepad, enter the filename in quotes as "BasicSandbox.wsb" so Notepad does not silently create BasicSandbox.wsb.txt.
Network-disabled and vGPU-disabled profile
For a test that does not need internet or accelerated graphics, save this as a file ending in exactly .wsb:
<Configuration>
<Networking>Disable</Networking>
<vGPU>Disable</vGPU>
</Configuration>
This profile reduces integration with the host and network. It does not turn Windows Sandbox into an absolute security guarantee, so keep Windows, drivers, and security software updated and avoid opening especially dangerous samples on a production computer.
How do you map a host folder as read-only?
Create the host folder C:SandboxInput, place only non-sensitive test files inside it, and use:
<Configuration>
<MappedFolders>
<MappedFolder>
<HostFolder>C:SandboxInput</HostFolder>
<SandboxFolder>C:UsersWDAGUtilityAccountDesktopInput</SandboxFolder>
<ReadOnly>true</ReadOnly>
</MappedFolder>
</MappedFolders>
</Configuration>
Read-only mapping prevents ordinary writes through that mapped path, but the mapping still exposes the folder’s contents to Sandbox. Do not map a sensitive directory merely because the mapping is read-only.
How do you run a mapped logon command?
A .wsb file can expose a script read-only and run it when the Sandbox user logs on:
Rank #4
- SonicWall Capture Advanced Threat Protection (ATP) For TZ570 - 5 Year License (02-SSC-5087)
- Multi-Engine Sandboxing Technology: Detects and blocks zero-day threats, ransomware, and unknown malware before they enter your network.
- Real-Time Deep Memory Inspection (RTDMI): Uncovers evasive, memory-based attacks that traditional defenses miss by analyzing code behavior at runtime.
- Seamless Firewall Integration: Works in tandem with SonicWall firewalls and security services for automated breach prevention and response.
- Cloud-Based Threat Intelligence: Leverages SonicWall's global GRID network to provide continuous updates and intelligent analysis of emerging threats.
<Configuration>
<MappedFolders>
<MappedFolder>
<HostFolder>C:SandboxScripts</HostFolder>
<SandboxFolder>C:Scripts</SandboxFolder>
<ReadOnly>true</ReadOnly>
</MappedFolder>
</MappedFolders>
<LogonCommand>
<Command>C:ScriptsInstall-Test-App.cmd</Command>
</LogonCommand>
</Configuration>
The script must exist at the mapped host location before launching the file. Test the configuration with harmless files first. XML element names and supported values can change with Windows releases, so compare advanced configurations with Microsoft’s current .wsb reference before deployment.
What changed in Windows 11 version 24H2 and version 22H2?
Windows Sandbox behavior is not identical across every Windows 11 release. Microsoft’s current installation documentation states that, beginning with Windows 11 version 24H2, inbox Store applications such as Calculator, Photos, Notepad, and Terminal are not available inside Windows Sandbox; Microsoft says support for those applications will be added later. This limitation applies to the documented 24H2 behavior and should not be generalized to every Windows 11 release.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBeginning with Windows 11 version 22H2, Microsoft documents that data can persist across restarts initiated within the Sandbox. The environment is still disposable when the Sandbox session closes. Treat files needed after closing Sandbox as temporary unless they are deliberately copied out through a controlled, non-sensitive path.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How do you troubleshoot Windows Sandbox?
Use the following order: verify edition, verify architecture and virtualization, confirm feature installation, check whether Windows is virtualized, check nested virtualization, inspect policy, then investigate servicing, drivers, and endpoint security.
Windows Sandbox is missing from Optional Features
- Confirm Settings > System > About > Windows specifications > Edition shows Pro, Enterprise, Education, or supported IoT Enterprise rather than Home.
- Confirm the device uses supported AMD64 or Arm64 hardware.
- Check Task Manager > Performance > CPU for Virtualization: Enabled.
- Determine whether Windows is running inside another virtual machine.
- Expose nested virtualization on the host if the hypervisor supports it.
- Install pending Windows updates and restart.
- Check whether organization policy or MDM restricts optional features.
Microsoft states that an unavailable Windows Sandbox option can mean the computer does not meet the required prerequisites. Do not assume that a missing checkbox is a user-interface defect.
The feature enables but Sandbox will not start
Restart Windows after installation, then check firmware virtualization, nested virtualization, Hyper-V-related configuration, Windows component-store health, graphics drivers, security software, and enterprise restrictions. A pending restart or build-specific defect can also prevent startup. If the failure occurs only when vGPU is enabled, disable vGPU in the profile and test again.
The .wsb file opens as text
The usual cause is a hidden second extension: filename.wsb.txt. In File Explorer, enable View > Show > File name extensions, rename the file so the final extension is exactly .wsb, and open it again with Windows Sandbox.
A mapped folder is unavailable
Confirm that the host folder exists, the path is spelled correctly, the XML is valid, and the Sandbox destination path is valid. Also check whether Group Policy or MDM disallows mapped folders, or whether permissions and endpoint security block access. Test with a new non-sensitive local folder rather than a cloud-sync root or protected personal directory.
Network access works when it should not
Check both the .wsb file’s <Networking> setting and organization-wide networking policy. A local profile should not be assumed to override centrally enforced policy. If network access is not required, use <Networking>Disable</Networking> and verify behavior with a fresh Sandbox session.
Windows Store applications are missing
On Windows 11 version 24H2, missing Calculator, Photos, Notepad, or Terminal applications inside Sandbox may be expected rather than evidence of a failed installation. Check the Windows version before treating the missing applications as a Sandbox startup problem.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- SonicWall Capture Advanced Threat Protection (ATP) For TZ570W - 1 Year License (02-SSC-5095)
- Multi-Engine Sandboxing Technology: Detects and blocks zero-day threats, ransomware, and unknown malware before they enter your network.
- Real-Time Deep Memory Inspection (RTDMI): Uncovers evasive, memory-based attacks that traditional defenses miss by analyzing code behavior at runtime.
- Seamless Firewall Integration: Works in tandem with SonicWall firewalls and security services for automated breach prevention and response.
- Cloud-Based Threat Intelligence: Leverages SonicWall's global GRID network to provide continuous updates and intelligent analysis of emerging threats.
Which Windows Sandbox settings are safest for suspicious files?
Use the minimum integration required for the task. A practical cautious profile disables networking and vGPU, uses no mapped folders, and leaves printer, audio, and video redirection disabled. If files must be supplied, place copies in a temporary, non-sensitive host folder and map that folder read-only.
- Disable networking unless internet access is essential to the test.
- Avoid mapped folders for Documents, Desktop, browser profiles, password stores, cloud-sync roots, source trees containing secrets, SSH keys, and cryptocurrency wallets.
- Prefer read-only mappings when a mapping is unavoidable.
- Disable vGPU when graphics acceleration is unnecessary because Microsoft documents a larger attack surface when vGPU is enabled.
- Disable printer, audio, and video redirection unless the test specifically needs those devices.
- Do not store secrets or treat the Sandbox as a permanent workspace.
- Use a full virtual machine when the workload requires snapshots, persistent disks, multiple operating systems, or complex networking.
Windows Sandbox reduces exposure through isolation, but no isolation feature should be presented as a promise that every malicious program is harmless. Use additional caution for high-risk samples and keep the host operating system and security tools current.
Should you use Windows Sandbox, Hyper-V, VirtualBox, or VMware?
Windows Sandbox is the fastest option for disposable Windows testing. A persistent hypervisor is more appropriate when a reader needs durable storage, snapshots, multiple guest operating systems, or a long-lived development environment.
| Option | Choose it when you need | Trade-off |
|---|---|---|
| Windows Sandbox | A quick, disposable Windows test session | Session state is not a durable VM environment after closing Sandbox. |
| Microsoft Hyper-V | Persistent Windows or Linux VMs on supported Windows editions | Requires VM storage, installation, updates, and resource administration. |
| Oracle VM VirtualBox | Persistent VMs, snapshots, and broader guest-OS flexibility | More setup and storage management than Sandbox; official site: VirtualBox. |
| VMware Workstation Pro | Persistent desktop VMs, snapshots, and advanced VM controls | Licensing and availability terms can change; confirm current terms on the official Workstation and Fusion page. |
| Windows 365 Cloud PC | A remotely hosted, persistent Windows environment | Requires recurring licensing, network access, and cloud administration; it is not a local disposable Sandbox. |
Microsoft Hyper-V is documented in the Hyper-V installation guide. Intune is more appropriate than local policy when an organization needs centralized management across enrolled devices, but Intune licensing depends on the selected plan and existing Microsoft 365 entitlements.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
How should you choose among the four enablement methods?
Choose the graphical Optional Features dialog for one personal computer. Choose PowerShell when the same setup must be repeated or automated. Choose DISM for deployment and Windows servicing workflows. Choose Group Policy or MDM when an organization must centrally restrict networking, folder access, vGPU, or peripherals. Use a .wsb file on top of the installed feature when users need repeatable task-specific profiles.
Frequently Asked Questions
Can Windows 11 Home enable Windows Sandbox?
Windows 11 Home does not include Windows Sandbox as a standard supported feature. Windows Sandbox requires a supported Windows 11 Pro, Enterprise, Education, or IoT Enterprise edition in addition to compatible hardware and virtualization.
Does Group Policy install Windows Sandbox?
No. Group Policy and MDM configure Windows Sandbox behavior after the optional feature is available. Enable the feature through Optional Features, PowerShell, or DISM first.
Does Windows Sandbox permanently save files after it closes?
No. Windows Sandbox remains disposable when the session closes. Windows 11 version 22H2 and later can preserve data across restarts made inside a running Sandbox, but that behavior is not durable storage after the Sandbox closes.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCan Windows Sandbox run inside a virtual machine?
Windows Sandbox can run inside a virtual machine only when the host supports and exposes nested virtualization, and the Windows 11 guest also meets the edition, architecture, resource, and feature requirements.
Why are Calculator, Notepad, Photos, or Terminal missing from Windows Sandbox?
On Windows 11 version 24H2, Microsoft documents that several inbox Store applications, including Calculator, Photos, Notepad, and Terminal, are unavailable inside Windows Sandbox. Missing applications on that release may therefore be expected.
The Bottom Line
For one Windows 11 PC, enable Windows Sandbox through Optional Features. Use PowerShell for automation, DISM for deployment or servicing, and Group Policy/MDM for centralized restrictions. After installation, use a .wsb profile to disable networking and unnecessary integrations, avoid sensitive mapped folders, and remember that policy configuration is not feature installation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

