Using Windows Sandbox for Safe Phishing URL Analysis with Network Isolation

Smith Oliver 80 Reputation points
2026-06-22T11:20:57.7733333+00:00

I want our IT security analysts to use Windows Sandbox to test suspicious URLs they find in phishing logs. By default, does Windows Sandbox inherit the host machine's network connection, and how can we isolate the sandbox network configuration so it cannot scan our internal corporate subnets?

Windows for business | Windows 365 Business
0 comments No comments

Answer accepted by question author
Harry Phan 32,835 Reputation points Independent Advisor
2026-06-22T14:10:38.12+00:00

Yes, Windows Sandbox automatically uses the same network connection as the host, so by default it can reach anything the host can, including internal company systems. If you want to stop analysts from scanning your corporate subnets, you’ll need to block that access at the firewall level. The simplest way is to create outbound rules in Windows Defender Firewall that apply only to the Sandbox process, allowing internet traffic but denying access to private IP ranges. Another option is to place the host in a VLAN or force Sandbox traffic through a proxy that blocks internal addresses. Microsoft doesn’t provide a built‑in “isolated network mode” for Sandbox, so the isolation has to be enforced with firewall or network configuration.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Oldest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.