If you have no good reason for your users to be accessing Microsoft Forms online, consider blocking it. Started seeing an uptick in the use of forms.microsoft[.]com as the lure URL in phishing emails about a month ago.
https://www.helpnetsecurity.com/2024/07/29/microsoft-365-phishing-forms/