Basically, it isolates the application from the operating system. You can't do so much in the GUI but using the sandboxie.ini you can block ports, internet domains, executables, partitions, folders, set read-only path to folders and registry keys etc.Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.
I recommend you guys this little piece of software.
HOMEPAGE
Bookmarks