When a change is made to an IPS policy new or existing that moves a process that is already running into another sandbox, the process must be restarted in order for it to be placed in the new sandbox. For more complex services and if OS service is assigned to a new sandbox a reboot of that machine will guarantee that any changes to the policy are applied fully to the OS.
This does not apply to IDS policies.