I gave Claude Code a brand-new Windows PC. Five things went wrong before it wrote a line. A developer documented five failures encountered while installing Claude Code on a clean Windows Sandbox machine, including the installer not adding the .local\bin folder to the user PATH, /logout exiting the tool, and a default auto-approval mode that let Claude write files without asking. The writeup provides fixes — a user PATH entry, a .claude/settings.json setting defaultMode to "default", and a PreToolUse hook that blocks Write and Edit outside the project folder — and reports the clean install took 32 minutes with 28 more for the hardened setup. Most Claude Code setup guides are written on a machine that already has years of tools on it. I wanted to see what a stranger's first hour actually looks like on Windows, so I gave Claude Code a machine that had never seen it and recorded everything. Five things went wrong before it wrote a single line of real code. All five are measured, all five have a fix, and one of them is a safety problem. My own PC has months of leftovers on it, so it can't show what a stranger sees. Windows Sandbox is a fresh copy of Windows every time you open it, and it forgets everything when you close it. That makes it a good test bench for "first install" questions. It isn't free, though. The Sandbox base image took 3.8 GB of my C: drive, and one rehearsal took my free space from 4.4 GB down to 2.2 GB. Check your free space before you start. Also: judge the Windows version by the build number. My Sandbox said "Version 2004", and only the build number told me what I was actually running. claude is still "not recognized" The official installer finishes cleanly, prints where it put Claude Code, and then tells you that folder is not on your PATH. On a clean machine it doesn't add it for you, so typing claude fails. The fix: add the .local\bin folder in your user profile to your user PATH. In PowerShell: Environment ::SetEnvironmentVariable 'Path', Environment ::GetEnvironmentVariable 'Path','User' + ";$env:USERPROFILE\.local\bin", 'User' Then close PowerShell completely, open a new window, and run claude --version . claude doctor will list a few things as "not fetched" before you sign in. That's expected, not an error. The first time you start Claude Code in a folder, it asks whether you trust that folder, and the highlighted answer is No, exit . Press Enter without reading and it just closes. The second one: /logout doesn't only sign you out. It exits Claude Code too. Neither is broken. Both will make a beginner think it is. A new install of Claude Code starts in auto mode. I asked it to list the folder and create a test file, and it wrote the file without asking me first. On someone's first day, that isn't what you want. The fix is a project settings file, .claude/settings.json , with the default permission mode set back to asking: { "permissions": { "defaultMode": "default" } } With that file in the project, the next start showed manual mode, and Claude asked before it wrote. I measured that in the same run. Claude Code's built-in sandboxing isn't supported on native Windows, so I added a guard: a small PreToolUse hook script that refuses file writes Claude's Write and Edit tools outside the project folder. It blocked a write to the Desktop and let a write inside the project through. But the first version also blocked plan mode. Plan mode saves its plans under your user profile, in ~/.claude/plans , which is outside the project. The fix was to allow that one folder. The lesson I'd keep: before you ship a guard, list every place the product itself writes. One honest limit: this guard covers Claude's file-writing tools. It is not a sandbox, and it does not stop a shell command from writing somewhere else. Asking before acting trap 3 is what covers that. The clean install, talking it through as I went, took 32 minutes. The secure setup took 28 more. Undoing everything took about 5. And the first draft of my undo list forgot the PATH entry I had added myself, which is its own small lesson: build an undo list by reversing your own steps, not by copying the vendor's uninstall page. The settings file and the guard script are free, plain text, and short. Read them before you use them: https://lgcreativestudios.github.io/buildwithaihub/ free https://lgcreativestudios.github.io/buildwithaihub/ free or straight from GitHub: https://github.com/lgcreativestudios/buildwithaihub/tree/main/book/windows-setup https://github.com/lgcreativestudios/buildwithaihub/tree/main/book/windows-setup . And remember: don't trust the report. Check the number. I'm an independent affiliate of ElevenLabs, Higgsfield and vidIQ. If you sign up through these links I may earn a commission, at no extra cost to you. The narration voices are AI ElevenLabs . The Sandbox run, the errors and the numbers are real. ElevenLabs and the ElevenLabs logo are registered trademarks or trademarks of ElevenLabs, Inc. Used with permission. buildwithaihub is not sponsored by, endorsed by, or affiliated with ElevenLabs except as an independent participant in the ElevenLabs Creator Affiliate Program.