Microsoft announces Windows Sandbox, a virtualized safe space for testing untrusted apps

Windows Sandbox isn't public, but it should be arriving soon for Windows Insiders.

Windows Sandbox is here to protect your PC. A simple, virtualized Windows within Windows, it’s a place where an app can be safely run if you’re worried it might be malware. 

Microsoft announced Windows Sandbox Tuesday evening in a blog post, unearthed by ZDNet. Microsoft pre-announced that Windows Sandbox would first be tested within a future Windows 10 Insider build, beginning with build 18305 or newer. (At press time, Windows Insider build 18298 was the latest public release.) You’ll need a 64-bit processor with virtualization enabled in the BIOS and within Windows, and either Windows 10 Server or Windows 10 Pro. Windows 10 Home users won’t be able to use Windows Sandbox.

Sandbox is a “isolated, temporary, desktop environment where you can run untrusted software without the fear of lasting impact to your PC,” Hari Pulapaka, the group kernel manager for the Windows kernel, desribed. “Any software installed in Windows Sandbox stays only in the sandbox and cannot affect your host. Once Windows Sandbox is closed, all the software with all its files and state are permanently deleted.”

Windows 10 Pro and Server can already create a virtual machine on your PC, which creates an copy of Windows that’s isolated from the host. Each time Windows Sandbox runs, Pulapaka said, it creates a “pristine” copy of Windows for testing. Unless the malware can somehow break out of that virtualized environment, Windows 10 Hyper-V (and Sandbox) should be able to create secure environments for testing. 

optional windows features dlg Microsoft

You’ll need to enable Sandbox first, before you begin using it.

Like Hyper-V, Windows Sandbox will not automatically be enabled. You’ll need to type “Windows Features” in the Search box and check the Sandbox box. Your PC will probably restart. Testing an app will then be as easy as running Sandbox and copying the app into the virtual environment.

Pulapaka noted that an app running in Sandbox will run in a somewhat lower-performance mode, because it’s using only part of the resources of your PC. (You’ll need at least 4GB of RAM, with 8GB recommended, 1GB of disk space, and at least 2 free CPU cores.) Microsoft engineered some tricks to reduce the VM’s size: It’s just 100 MB when actually running. And although the initial boot time will take some time, Microsoft will freeze the state of the VM, post-boot, and refer to it when opening future instances of Sandbox—reducing that boot time significantly. Sandbox will also be able to virtualize some of the PC’s graphics resources.

“The whole goal here is to treat the Sandbox like an app but with the security guarantees of a Virtual Machine,” Pulapaka wrote.

What this means to you: Virtualization is a key component of helping secure apps and websites that you may not trust: Windows Device Application Guard, for example, is a little-known secure browser within your PC for browsing untrusted sites. You may never need to use Windows Sandbox, but the idea is that it’s a safety net, and a tool to use if you’re just not that sure about whether an app is truly safe. 

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Mark Hachman

Mark Hachman

PC World (US online)
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?