Allow vGPU sharing for Windows Sandbox
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Windows Sandbox Description
This policy setting is to enable or disable the virtualized GPU. If you enable this policy setting, vGPU will be supported in the Windows Sandbox. If you disable this policy setting, Windows Sandbox will use software rendering, which can be slower than virtualized GPU. If you do not configure this policy setting, vGPU will be enabled. Note that enabling virtualized GPU can potentially increase the attack surface of the sandbox.
Registry
SOFTWARE\Policies\Microsoft\Windows\Sandbox Value name: AllowVGPU
Enabled: AllowVGPU = 1
Disabled: AllowVGPU = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowVGPU Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
CSP values
-
0- Not allowed. -
1 (Default)- Allowed.
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Allow vGPU sharing for Windows Sandbox
; State: Enabled
; Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox]
"AllowVGPU"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowVGPU' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/WindowsSandbox/AllowVGPU
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowVGPU' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowVGPU' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox' -Name 'AllowVGPU' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Allow vGPU sharing for Windows Sandbox
# State: Enabled
# Supported on: At least Windows 11 Pro, Enterprise, or Education with Windows Sandbox
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\Sandbox'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'AllowVGPU' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.