How to Enable and Configure Windows Sandbox on Windows 11
Learn how to enable Windows Sandbox to test suspicious programs safely and configure it using .wsb files for shared folders, network settings, and RAM.

On this page
Unlike a virtual machine, you don’t need to download a Windows image or install anything: it uses the system files you already have, starts up in seconds, and doesn’t take up disk space. In exchange, it saves nothing between sessions, which is exactly its purpose.
When to use it #
- To test a program downloaded from an untrusted site without risking that it fills your PC with unwanted components.
- To open a suspicious attachment received via email to see what it contains without running it on your actual computer.
- To check an installation before actually performing it: seeing what it adds, what permissions it requests, and which files it creates.
- To visit a website you don’t trust using a browser that is isolated from everything else.
For everyday use, however, it isn’t necessary: it doesn’t save anything, so every time you start it, you begin from scratch.
Requirements #
- Windows 11 Pro, Enterprise, or Education (Pro Education and SE are also fine). The Home version does not include it.
- A 64-bit processor with virtualization enabled in the BIOS or UEFI.
- At least 4 GB of RAM (8 GB is better) and a couple of gigabytes of free disk space.
How to check if virtualization is enabled
Open Task Manager using Ctrl + Shift + Esc, go to Performance → CPU, and look at the Virtualization line: it must say “Enabled.” Alternatively, open Terminal and run systeminfo: at the bottom, under the Hyper-V requirements section, Virtualization enabled in firmware should be Yes.
If it is disabled, you can turn it on from the BIOS or UEFI. Depending on the manufacturer, it may be called Intel VT-x, AMD-V, SVM Mode, or Virtualization Technology.
Enable Windows Sandbox #
In the Start menu, search for Turn Windows features on or off (or type
optionalfeaturesin Run) and open it.Scroll down the list to Windows Sandbox, check the box, and click OK.
Click OK and wait for Windows to install the components.
Restart your computer when prompted.
After restarting, you will find Windows Sandbox in the Start menu. A window will open with a clean desktop: you can copy and paste files from your computer into it, browse, install, and test things. When you close it, everything is deleted, and the confirmation message is there specifically to remind you of that. However, if you restart Windows inside the sandbox (which happens when programs request a restart during installation), starting from Windows 11 22H2, the content will remain.

In recent versions of Windows 11, the three-dot menu at the top of the window allows you to change certain settings on the fly without configuration files: sharing a computer folder (Share Folder), enabling or disabling shared clipboard, microphone, and webcam.
Configure it with a .wsb file #
The behavior of the sandbox is determined by a small XML file with an .wsb extension: just double-click it and the sandbox will start already configured. You can create one using Notepad, saving it with an .wsb extension instead of .txt (in Save As, select All files).
This one is ready to use for analyzing a suspicious file: network off, one computer folder shared as read-only, and 4 GB of memory.
<Configuration>
<Networking>Disable</Networking>
<MemoryInMB>4096</MemoryInMB>
<vGPU>Disable</vGPU>
<MappedFolders>
<MappedFolder>
<HostFolder>C:\Users\NomeUtente\Desktop\DaAnalizzare</HostFolder>
<SandboxFolder>C:\Users\WDAGUtilityAccount\Desktop\DaAnalizzare</SandboxFolder>
<ReadOnly>true</ReadOnly>
</MappedFolder>
</MappedFolders>
</Configuration>
Replace NomeUtente with your username and make sure the folder specified in HostFolder exists; otherwise, the sandbox will not start.
The second example is for testing a program installation: network on, a folder shared as read/write, and a command that opens it upon startup.
<Configuration>
<Networking>Default</Networking>
<MappedFolders>
<MappedFolder>
<HostFolder>C:\Users\NomeUtente\Downloads\Prove</HostFolder>
<ReadOnly>false</ReadOnly>
</MappedFolder>
</MappedFolders>
<LogonCommand>
<Command>explorer.exe C:\Users\WDAGUtilityAccount\Desktop\Prove</Command>
</LogonCommand>
</Configuration>
Available options #
| Element | Purpose |
|---|---|
Networking | Disable removes the network, Default keeps it active |
MappedFolders | Computer folders visible inside the sandbox |
ReadOnly | With true the sandbox cannot modify shared files |
MemoryInMB | Assigned memory, in megabytes |
vGPU | Graphics acceleration: disabling it reduces the attack surface |
ClipboardRedirection | Disable prevents copying and pasting between the sandbox and your computer |
LogonCommand | A command to be executed at startup |
ReadOnly on true. A folder shared as read/write is an exit route for a program that encrypts or deletes files. In read-only mode, the damage stays contained within the sandbox.You can keep multiple .wsb files with different configurations—for example, one for analysis and another for installation tests—and launch whichever you need with a double-click.

Starting from Windows 11 24H2, there is also a command line tool, wsb, which is useful for automating tests: wsb start --config it launches the sandbox with a configuration file, wsb exec executes a command inside, wsb share shares a folder and wsb stop closes it.
Limitations to keep in mind #
It doesn’t save anything. If you install a program and close the window, it won’t be there when you reopen it. This is by design, but remember that before spending an hour configuring something.
Only one sandbox at a time. You cannot open two at once.
It is not a replacement for a virtual machine. To test other operating systems, save a state over time, or simulate a network of computers, you need actual virtualization software.
It’s not an absolute guarantee. The isolation is solid because it is based on the hypervisor, but no barrier is perfect; with the network active and write access to shared folders, you are effectively lowering part of that protection.
FAQ #
Does Windows Sandbox slow down your computer? #
Only while it is open, and in proportion to how much memory you allocate to it. When closed, it consumes nothing because there are no active processes. On a PC with 8 GB of RAM, limit it to 2 or 4 GB using the MemoryInMB option.
Can I recover a file saved inside the sandbox? #
No, once you close the window, the content is lost forever. To keep something, use a shared folder with write access, or copy the file to your computer before closing.
Why can’t I find “Windows Sandbox” among the features? #
Either you are using Windows 11 Home, which does not include it, or virtualization is disabled in your BIOS. In the first case, your options are to upgrade to Windows 11 Pro or use free virtualization software like VirtualBox; in the second case, simply enable virtualization in your firmware.

Does the sandbox protect against ransomware? #
It helps, but it depends on how you configure it. A malicious file opened in the sandbox won’t touch your main system, but it can reach shared folders with write access and, if the network is active, other devices. With the network turned off and folders set to read-only containment is much more robust.
What is the difference between a sandbox and a virtual machine? #
A virtual machine saves its state, allows you to install different operating systems, and can be configured in great detail, but it takes up disk space, needs to be installed, and takes a few minutes to boot. The sandbox starts in seconds, takes up no space, and resets every time: it is designed for quick testing, not for stable daily work.

