A full VM you never install
The feature ships as an optional component: turn on Windows Sandbox in the Windows Features dialog (optionalfeatures.exe) or with a single DISM command, and a Start-menu entry appears. The requirements are modest but firm: Windows Pro or Enterprise, virtualization enabled in the firmware, at least 4 GB of RAM with two cores, and a gigabyte or two of free disk for the working files.
What you get is a clean, unactivated Windows in a window, with networking, clipboard sharing and copy-paste working out of the box. Under the hood it is a real lightweight VM running on the Hyper-V hypervisor — not a container, not a remote session — just one that pretends nothing happened when you close it.
Where the disk image goes — and why it vanishes
At launch, the sandbox mounts a pristine system image read-only and builds a temporary write-on-top layer — a disposable VHDX — for everything you do inside. At shutdown that layer is destroyed by design, which is why the machine you were just using has evaporated, files and all.
- The base image is a clean Windows snapshot; the sandbox never sees your installed apps or your files
- Everything you do inside lands in a temporary VHDX that exists only while the sandbox runs
- On close, the whole layer is discarded: no files, no registry changes, no installed programs survive
- Clipboard copy-out and mapped folders are the only legitimate ways to keep something
- After a crash or power loss, leftover working files in temp folders are safe to delete once the sandbox is closed
- Don't move real work there: a sandbox session is the wrong home for anything you want tomorrow
When to use it, and when a real VM is better
The sweet spot is short, suspicious work: opening that sketchy installer, testing a download that promises too much, checking a link you'd rather not feed your main browser. A session costs you a minute, and the blast radius is zero. A .wsb config file can lock it down further — disable networking, turn off the virtual GPU, map one folder read-only — which is the right posture for genuinely hostile files.
What it is not is a second PC. There is no snapshot you keep, no state between runs, no way to install your toolkit once and reuse it — for that, a full VM (or WSL for Linux work) is the honest answer. If you need to keep what you test, keep it in a VM; if you need to be sure it's gone, that's the sandbox's whole job.
Questions and Answers
Is Windows Sandbox safe for testing viruses?
Safer than your main system, but not a substitute for an isolated lab: with networking enabled, malware can still reach your network. Disable networking in a .wsb file for hostile samples.
Why did everything in Windows Sandbox disappear?
By design. The sandbox runs on a disposable disk image that is destroyed when you close it; nothing inside persists between sessions, which is exactly the point.
Know what is included before you buy.
The one-time 30-minute trial covers core tools. PRO-labelled features stay locked until a paid license is activated.
Read next
Write to us: [email protected]