The configuration doesn't matter, nor does the actual Containment level (Partially Limited works just fine). Note also that the Firewall at Safe Mode will alert to the ransomware attempting to infect others on the Network,
Also for giggles, in addition to this one from the Darkside Group I also ran a few newer files that are all the rage this month on TOR. They come from what my friends at Mandiant have labeled as the UNC2447 group. Related to Deathransom (HelloKitty), the variants tested were FIVEHANDS and Sombrat. All were contained without any system changes.
Why Industry doesn't use Comodo Endpoint is beyond me...