Treat it as safe only if the form clearly explains how the data will be used and it does not ask for highly sensitive information such as passwords.
Relevant Microsoft Forms guidance:
- Microsoft advises not providing sensitive personal information when a form does not include a privacy statement about how response data will be used.
- To help prevent phishing, forms should not ask for sensitive personal information such as passwords.
- If a form is collecting anonymous responses and appears to be maliciously gathering user information, use the Report Abuse link at the bottom of the form and select phishing.
- Microsoft Forms supports responses from people outside an organization, and those responses can be submitted anonymously, so anonymity alone does not prove the form is trustworthy.
A practical check is:
- Look for a privacy statement or clear explanation of how the responses will be used.
- Do not enter passwords or similarly sensitive secrets.
- If the form seems suspicious, do not submit it and use Report Abuse.
References: