So I have done further testing as I believe the issue is with BitLocker being enabled before the Sandbox feature is enabled. All machines are physical systems.
Test 1 - Disable BitLocker on an existing machine. Sandbox error about "media being write protected" persists.
Test 2 - Clean install of machine, off domain. Sandbox works.
Test 3 - Join clean install to domain. Sandbox still works.
Test 4 - Enable BitLocker on newly domain-joined system. Sandbox still works.
Test 5 - Apply group policies as required by the OU placement. Sandbox still works.
It appears that enabling the Sandbox feature on a system that had BitLocker enabled before is the key culprit with the "media is write protected" error. Anyone else having this problem yet? I haven't found any update from MS on this issue and the recent CU didn't fix it.