form-basics

How to make a Microsoft Forms survey anonymous, and when it is not

October 8, 2026 ・ Halict Editorial

The question usually arrives from the other direction. Someone is about to send out a staff pulse survey, an exit questionnaire or a complaint form, and a colleague asks whether the answers can really not be traced back. The honest answer has two parts: there is one checkbox that decides whether Microsoft Forms stores a name against each response, and there are several ways a response can still be identified after that checkbox is cleared. Both parts matter, and most guides only cover the first.

The setting is called Record name, and it lives under who can respond

Open the form and select Settings on the top action bar. The pane that opens has a section for who can fill out the form, with three choices. Two of them, Only people in my organization can respond and Specific people in my organization can respond, carry a Record name checkbox. Clear it, and names stop being stored with responses.

The third choice, Anyone can respond, has no such checkbox because it does not need one. Microsoft's documentation describes it plainly: responses automatically come in without names recorded. If a form is open to the public, it is already nameless as far as Forms is concerned.

There is a catch worth knowing before the survey goes out. Clearing Record name also removes the One response per person option, which sits directly beneath it. That pairing is not a bug. Forms can only stop a second submission from the same person if it knows who the person is. Anonymity and one vote each are mutually exclusive in this product, and any plan that assumes both will fail at the first duplicate.

Account type changes the picture too. The Record name setting appears for Microsoft 365 work and school accounts. On a personal Microsoft account, meaning Hotmail, Live or Outlook.com, the setting is not offered at all, and forms are automatically set to collect responses without names recorded. Somebody following a walkthrough written for a work tenant will look for a checkbox that was never there and conclude the feature is broken.

What Forms still records once the name is off

Clearing the checkbox stops one specific thing: the identity column in the response table. Several other things continue.

Submission time is still recorded, to the minute. On a survey of eight people sent on a Tuesday afternoon, the order of arrival is often enough to reconstruct who said what, especially if one person is known to work a different shift or a different time zone.

Free text is still free text. A comment that mentions a manager by name, a project only one team touches, or a grievance that has already been raised verbally will identify its author regardless of what the response table stores.

And the questions themselves keep working. Ask for department, tenure band, job level and location on a survey of forty people, and the cross tabulation of four fields narrows most responses to one person. Microsoft's own guidance notes the same risk in plainer terms: names can still be recorded if a question asks for personally identifiable information and the respondent supplies it.

What the reader wants What clearing Record name does What it does not do
No name in the response table Yes, names are not stored
No way to work out who answered Timestamps, free text and demographic questions all remain
One response per person Option becomes unavailable
Respondent can see it is anonymous Removes the name notice on the form Gives no positive confirmation
No record at the tenant level Tenant admins retain the usual administrative controls over forms

The distinction that matters is between unattributed and untraceable. Forms gives the first reliably. The second is a property of the questions, the population size and the wording, not of a checkbox.

How a respondent can tell before answering

This is the part that generates the most searching, because Microsoft does not document a way for respondents to verify the setting. What exists is a negative signal.

When a form does record names, respondents see a line above the questions stating that when the form is submitted, the owner will be able to see their name and email address. The notice cannot be edited or hidden while the setting is on. If that line is present, the form is attributed. If it is absent on a form that requires sign-in, names are not being recorded.

That is a usable check, but it is weak, and it is the reason anonymous surveys run inside a company so often fail to get candid answers. The absence of a warning is not the same as a stated promise. A survey that depends on candour is better served by saying explicitly in the form description what is collected, what is not, who will read the responses and in what form the results will be shared. Stating it costs one paragraph and changes the response rate more than the checkbox does. The other failure to plan for is the opposite one: a survey so carefully stripped that the results cannot be acted on. If the finding is that one department is unhappy and the form did not ask which department, the survey has cost everyone an afternoon and produced a fact nobody can use. Decide first which single cut of the data will change a decision, ask for that one, and leave the rest out. That choice does more for both candour and usefulness than any setting in the pane.

When an anonymous form is the wrong tool

There is a category of form that gets marked anonymous out of caution and then cannot do its job. Three cases come up repeatedly.

Anything that needs a reply. A complaint form, a maintenance request, an IT issue, a whistleblowing channel where the reporter wants an outcome. Strip the identity and the response arrives as a problem with no one to answer. Teams then work around it by adding an optional email field, at which point the form is neither anonymous nor properly attributed, and nobody can say which responses are which.

Anything that needs deduplication. Voting, registration, allocation of limited places. As covered above, this is structurally incompatible with clearing Record name.

Anything that needs follow up over time. A survey run quarterly to track whether a problem improved needs at least a stable pseudonym, and Forms does not issue one.

For the first case in particular, the better shape is not an anonymous form but a form where the identity is collected and access to it is controlled. Anonymity protects the respondent by deleting information. Access control protects them by limiting who sees it, which leaves the response answerable. A form tool with response management can hold the submission, assign an owner, carry a status and send the reply from the same record, with view only roles for people who should see progress but not contact details. That is a different guarantee, and for anything that needs an answer it is the more useful one.

Running an anonymous survey for people outside the organization

The moment the audience includes anyone without a login in the tenant, the only sharing option that works is Anyone can respond, and that setting brings anonymity as a side effect rather than as a choice. Two consequences follow.

The link is a bearer token. Anyone holding it can submit, and it can be forwarded. For a customer satisfaction survey that is normally fine, because a stray response is noise rather than harm. For anything that allocates something scarce, such as places at an event or entries in a draw, the open link is the whole attack surface, and there is no way to close it without reintroducing sign-in and therefore names.

Volume ceilings differ sharply by account, and this is where public surveys run into a wall that internal ones never meet. Microsoft documents up to 5,000,000 responses per form for Office 365 Education, Microsoft 365 Apps for business and GCC accounts. Personal Microsoft accounts are capped far lower, at 200 responses on a free account and 1,000 on a paid one. A public survey built on a personal account can therefore close itself in an afternoon if the link travels further than expected.

One more limit matters for anyone planning to deduplicate later by hand rather than through the setting. Microsoft notes that the one response per person guideline is only enforced within a continuous set of 50,000 responses and is not guaranteed across a larger data set. Any deduplication strategy on a high volume public form has to happen in the analysis, not in the form.

The workable shape for external anonymous surveys is therefore short, blunt and low stakes. Keep the question count low, keep the demographic questions to the one or two dimensions the analysis actually needs, and decide in advance what a suspicious cluster of responses will mean, because the form will not tell you.

The half measures worth skipping

Two workarounds circulate and neither holds up.

The first is to leave Record name on and delete the name column after exporting. The export is a snapshot; the form keeps the identities, and anyone with access to the form sees them. Telling respondents the survey is anonymous while this is the arrangement is a claim that the product will contradict.

The second is to set the form to Anyone can respond purely to get anonymity, without thinking about distribution. That does produce nameless responses, and it also means the link works for anyone who receives it, including outside the organization. For a staff survey circulated by email that is usually an acceptable trade. For anything where the population must be controlled, it is not, and the honest options narrow to accepting attributed responses or accepting an uncontrolled audience.

Where the responses go afterwards, and who can read them

One more thing decides whether an anonymous survey is genuinely private in practice: what happens to the results.

Selecting Open in Excel from the Responses tab produces a workbook with a live connection to the form, stored in OneDrive for work or school, or in SharePoint for a group form. That file inherits the sharing behaviour of wherever it lands. A survey that was careful about names and careless about the workbook's permissions has protected nothing. It is worth checking who can open that file before the first response arrives, not after.

Group forms deserve a second look for the same reason. A form created in a Microsoft 365 group or a Teams team is owned by the group, so every member can see the responses. That is often exactly what is wanted for a shared intake queue and exactly what is not wanted for a survey about the team's own management.

What to change first

Open the form, clear Record name, and then read your own questions back as an attacker would: given forty respondents, which combination of answers points at one person. Fix the questions before you fix anything else, because that is where anonymity is actually won or lost. If the form turns out to need a reply rather than anonymity, the change to make is controlling who can see the identity instead of deleting it, which is what Halict is built around.

Q1. Is Microsoft Forms anonymous by default?

It depends on the account. Forms created with a personal Microsoft account collect responses without names recorded automatically, because the Record name setting is not offered. Forms created with a Microsoft 365 work or school account record names by default when the audience is restricted to the organization, and the setting has to be cleared deliberately.

Q2. Can the form owner see a respondent's IP address in Microsoft Forms?

Microsoft does not expose an IP address in the response data that a form owner reads or exports. What the owner does see on every response is the submission time, which on a small survey is often enough to narrow down who answered.

Q3. Why does One response per person disappear when Record name is turned off?

The two settings depend on each other. Forms can only enforce a single submission per person by identifying the person, so clearing Record name removes that option. A survey cannot be both nameless and deduplicated in this product.

Q4. How can respondents be shown that a survey really is anonymous?

There is no built in confirmation for respondents. The only signal is the absence of the notice saying the owner will see their name and email address. Anything stronger has to be written into the form description by hand, stating what is collected and who reads it.

Q5. Does clearing Record name hide responses from IT administrators?

No. The setting controls what is stored against each response for the form owner. Tenant administrators retain the administrative controls over Forms that their role grants, so the setting is a promise about attribution in the results, not about what the organization can never access.

All guides