I'm sorry but there is no level of user education that will protect a large organisation from phishing links. The attack surface is way too large and safety depends on how the user is feeling on any given day when a random email turns up. There are no high reliability systems that require manual user interaction on a frequent basis especially on low-effort low-concentration tasks.