You'll need to enter a bogus process name. *.exe should work; or some other name like noprocessallowed.exe. Make it strange enough... But yes, it would be great to be able to block all programs, without having to specify bogus process names. Something that I noticed is that, if you use this approach, while still forcing a real process name to start under the sandbox, is that Sandboxie won't automatically clean the sandbox. I have to do it manually. It's a bit awkward to be like this. For instance, I'm forcing Adobe Reader to start under a dedicated sandbox, but I only allow acrord32_block.exe to start, so that Adobe Reader fails to run. But, Sandboxie won't automatically delete the contents of the sandbox. I wish this behavior could change.