Yes, Windows Sandbox automatically uses the same network connection as the host, so by default it can reach anything the host can, including internal company systems. If you want to stop analysts from scanning your corporate subnets, you’ll need to block that access at the firewall level. The simplest way is to create outbound rules in Windows Defender Firewall that apply only to the Sandbox process, allowing internet traffic but denying access to private IP ranges. Another option is to place the host in a VLAN or force Sandbox traffic through a proxy that blocks internal addresses. Microsoft doesn’t provide a built‑in “isolated network mode” for Sandbox, so the isolation has to be enforced with firewall or network configuration.
Using Windows Sandbox for Safe Phishing URL Analysis with Network Isolation
Smith Oliver
80
Reputation points
I want our IT security analysts to use Windows Sandbox to test suspicious URLs they find in phishing logs. By default, does Windows Sandbox inherit the host machine's network connection, and how can we isolate the sandbox network configuration so it cannot scan our internal corporate subnets?
Windows for business | Windows 365 Business
Answer accepted by question author
Harry Phan
32,835
Reputation points
Independent Advisor