Information
This policy setting enables or disables clipboard sharing with the Windows Sandbox.
The recommended state for this setting is: Not allowed
Note: The Windows Sandbox feature was first introduced in Windows 10 R1903, and allows a temporary 'clean install' virtual instance of Windows to be run inside the host, for the ostensible purpose of testing applications without making changes to the host.
Disabling copy and paste decreases the attack surface exposed by the Windows Sandbox and possible exposure of untrusted applications to the internal network.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Not allowed
Windows Sandbox\Allow Clipboard Redirection
Impact:
The copy and paste function to/from the Windows Sandbox will be disabled. Therefore, files will not be able to be moved to/from the Windows Sandbox via the clipboard.