## What changed
- Add `WindowsSandboxConfig` helpers to read app-server configuration and managed requirements, preserve legacy feature flag fallbacks, and select an allowed setup mode with elevated mode preferred when the configured mode is disallowed.
- Store the sandbox host classification in thread session state using reported environments across start, resume, fork, and replay paths. Classify missing or empty environments as `Unknown`, and distinguish local, remote, and mixed selections.
## Testing
Add coverage for managed setup restrictions, legacy configuration precedence, unknown policy state, environment classification, and remote host state in inactive-thread replay.
GitOrigin-RevId: ae8920d9c2a1c80b641ac90617ae607b171bd55a