The Xbox Developer Portal (XDP) offers the convenience of a single, consistent development environment for your Xbox One content-including secure run-time access to the product instances that you place in your development sandboxes.
The system that we use to keep your intellectual property safe in a sandbox is called Content Isolation.
Content Isolation ensures that you have complete control over which users and devices have access to your sandboxed content.
Sections in this topic:
The effectiveness of Content Isolation is based on the fact that your organization owns all three of the following processes:
To access and run the product instances in a sandbox, a user must log on by using the credentials of a development account that is owned by an XDP user account-and not by using the credentials of the XDP user account itself.
In addition, either the user account that owns the development account or the device from which the user is logging on must belong to an access group that has been granted run-time access for the sandbox.
The following three examples illustrate the effects of these requirements.
In the first example, two users attempt to access a sandbox in run time by using the credentials of their XDP user accounts.
The “authorized” user account belongs to a group that has been granted access for the sandbox, while the “unauthorized” user account does not belong to such a group.
But because sandboxes can only be accessed in run time by using development account credentials-and not XDP user account credentials-in this case, neither user achieves access.

The devices in this first example are both “unauthorized” in that neither of them belongs to a group that has been granted access for the sandbox.
In the second example, each of the users makes another attempt to log on, each this time by correctly using the credentials of a development account that is owned by their XDP user account.
This time, the “authorized” user is able to achieve access, because the XDP user account to which the development account belongs is a member of a group that has been granted run-time access for the sandbox.
The “unauthorized” user, whose XDP user account does not belong to a group that has been granted access, fails again.

In the third example, the only change in the configuration is that the “unauthorized” user is now logging on from an “authorized” device-a device that belongs to a group that has been granted access for the sandbox-and now this user, too, is able to achieve access.
A user does not need to own an XDP user account in order to use the logon credentials of an Xbox One development account.
There are a variety of scenarios in which it is useful for a publisher or developer to lend the logon credentials of a development account owned by one of their own XDP user accounts to a third-party user who does not have an XDP user account of their own.
Using such “loaned” development-account credentials, the third-party user can log on in the same way that the owner of the account would do.
As explained above, either:

Using Content Isolation, you can control run-time access to your Xbox One content both securely and confidently.