Aident AI

Codex Computer Use EnumWindows 0x80070003? Test the Desktop Boundary
If Codex Computer Use on Windows fails at sky.list_apps() or sky.list_windows() with EnumWindows failed: The system cannot find the path specified. (0x80070003), stop reinstalling components. Current reports show the helper can exist, start, and answer diagnostics while window discovery still fails. A successful compatibility test on one affected machine points to the desktop isolation boundary as a cause for at least one configuration.
The narrow compatibility test is to keep the elevated Windows sandbox, temporarily set windows.sandbox_private_desktop = false, fully restart Codex, and retry one read-only window listing. OpenAI documents this setting as the older Winsta0\\Default compatibility path and warns that the private desktop provides stronger UI isolation. Treat the test as a diagnosis with a rollback, not as a permanent security recommendation.
Confirm This Exact Failure
This guide applies when all of these are true:
Computer Use is installed and enabled in Codex on Windows.
The failure happens before Codex can select or approve a target application.
Both
sky.list_apps()andsky.list_windows()return0x80070003, or the closely related0x80070002file-not-found variant.The bundled
@oai/skypackage imports and the Computer Use helper starts.
Use a read-only prompt for the reproduction:
Preserve the exact error, Codex app version, Computer Use plugin version, Windows version, architecture, and UTC time. Redact user names, account identifiers, local paths, window titles, screenshots, and feedback IDs before sharing logs publicly.
Five independent OpenAI issue reports opened from August 5 through August 7, 2026 describe the same EnumWindows boundary on Windows 10 and 11, x64 and ARM64. The longest report records successful helper startup, a healthy direct Win32 enumeration test outside the sandbox, and failure only when the Computer Use helper enumerates windows. That evidence points away from a missing executable or a dead Windows desktop.
Do Not Repeat Failed Repairs
The reports already cover these attempts without restoring enumeration:
repairing, resetting, uninstalling, and reinstalling Codex;
reinstalling the Computer Use plugin;
rebuilding the
cua_noderuntime;restarting Codex and Windows;
reinstalling Workspace Dependencies;
toggling app access and checking that the desktop is active and unlocked;
creating missing profile folders or changing window-station access controls.
Do not weaken ACLs, disable UAC, grant broad desktop permissions, replace the signed helper, or install a custom broker from an issue comment. Those changes expand the security problem without establishing the cause.
This failure is also different from Error: node_repl exec context not found. If enumeration succeeds and a later JavaScript call loses its context, use the Codex Computer Use node_repl containment guide. If the helper never starts and the error says spawn EPERM, use the separate Windows Computer Use spawn diagnostic.
Run One Reversible Compatibility Test
Open your reviewed Codex configuration file. If it already contains a [windows] table, edit that table instead of creating a duplicate. Preserve any existing values and add only the compatibility setting:
Do not change the sandbox implementation as part of this test. If the table already has sandbox = "elevated", leave it in place. Do not switch to full access, disable approvals, or turn off the Windows sandbox. OpenAI's Windows sandbox documentation says both native sandbox modes use a private desktop by default for stronger UI isolation and recommends sandbox_private_desktop = false only when the older Winsta0\\Default behavior is needed for compatibility.
Fully exit Codex and any related ChatGPT desktop process through the normal app controls, then launch a fresh task. Repeat only the read-only listing prompt.
Expected result:
sky.list_windows()orsky.list_apps()returns visible application metadata;no window is clicked, focused, captured, or changed;
the original
0x80070003error no longer appears.
If the error is unchanged, restore the original configuration immediately. The private-desktop boundary was not a sufficient explanation for that installation, so record the result and wait for an upstream fix instead of applying broader permissions.
Understand the Security Tradeoff
The private desktop is a security boundary, not a performance option. It isolates UI-capable sandbox processes from the user's interactive desktop. Setting it to false lets the compatibility path use Winsta0\\Default, which can make real windows visible to Computer Use.
That explains why one issue participant restored enumeration with the setting, but it does not prove the complete Computer Use workflow is repaired. The same report still observed a later node_repl context failure and a screen-capture service error. Window listing, screen capture, and interaction are separate gates.
For a safe test:
Use a disposable, non-sensitive application with no account, message, terminal, password, or private document visible.
Keep normal approvals enabled.
Test only window enumeration first.
Do not test credential dialogs, security settings, terminals, Codex itself, or other privileged surfaces.
Remove the explicit
sandbox_private_desktop = falseline after the test, or restore it to its prior value, then fully restart Codex again.
Success means you identified the boundary and restored the stronger default afterward. Leaving the compatibility setting enabled is a separate risk decision that should follow your organization's security policy and OpenAI's current guidance.
Verify the Rollback
After removing the temporary override, fully restart Codex and repeat the read-only listing prompt.
Expected result: the original behavior returns if the issue is still present upstream. That may feel like a failed repair, but it proves the rollback restored the stronger isolation boundary and that the compatibility test was causal.
If a future Codex or Computer Use update fixes the issue, test again with the private desktop enabled. Do not preserve a weaker compatibility setting after the supported path works.
For a case where Computer Use is missing only from project tasks but available elsewhere, follow the project capability visibility guide instead.
Keep External Work Moving Without UI Control
While the upstream Windows boundary is unresolved, use typed provider Actions for tasks that do not require screen control. Aident Loadout can search a connected service, inspect the current schema, estimate cost, and run one bounded read-only Action without exposing a provider key to the prompt.
Give Codex the canonical setup instruction:
Follow https://aident.ai/SETUP.md
Then use this prompt:
Check my Aident Loadout account and Vault status. Search the staging capability catalog for a connected read-only Hacker News search Action, inspect its current schema, and preflight it. If the estimate is free, search for "Codex Computer Use Windows" and return only matching titles and URLs. Do not publish, comment, edit, install, change files, or ask me for a provider key.
Success is measurable: account status, Vault status, discovery, schema inspection, preflight, and one read-only search complete without Computer Use; no provider credential appears; and no external write occurs. Set up Aident Loadout and run the read-only alternative.
Sources
OpenAI Codex issue 37255: Windows Computer Use cannot enumerate windows
OpenAI Codex issue 37383: failure persists on the newer Computer Use build
Refresh this guide when issues 37043, 37255, or 37383 change state, OpenAI changes the sandbox_private_desktop guidance, a Computer Use release restores private-desktop enumeration, or the compatibility setting no longer affects the failure.



The one tool
for every tool
your agent needs.
Give any AI agent real capabilities in seconds. Connect 1,000+ tools once, skip the setup headache, and let your agents execute.
