Historically sandboxie prevented sandboxed applications from using job objects as it used this mechanism to apply some restrictions itself and older windows versions did not support processes withing a restricted job spawning processes in own jobs, a.k.a. nested jobs, this changed with windows 8. So there is no more reason to prevent boxed processes from using own job objects to apply additional isolation of their workers, like for example the chromium sandbox does. I would like to enable this functionality by default in one of the upcoming builds, as it enhances the isolation. Here you can find this option, I don't expect it to break compatibility with anything but before I roll it out enabled by default, please enable it for testing and report back if it truly does not break anything.