You have granular control over universal windows apps (ie windows 8+ apps) and one global lock over all desktop apps (non uwp), and one global lock over everything. It's pretty solid considering how little control Microsoft has and it's wonderful fetish for compatibility.
Tldr basically same as Linux, except app distribution in Linux was bad enough for so long that more stuff is in the new restricted format while windows still has tons of things which will never go away and aren't in the sandbox. I think not finding a way to sandbox all desktop apps was a mistake.
Yeah god knows I was never like that as a kid, wishing I could be home playing my N64 instead of sitting on a car ride for hours and hours and hours on end. Who would ever prefer video games to the freshly recycled air pumped over you for the 100000th time that day while staring out at corn?