The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn't going to make any kind of effort towards it. That's on you, not on us!
Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you're redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing... why wouldn't it just be login.microsoft.com? I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you're dumping your credentials into random looking domains, then downloading and installing software from other random domains.
They just don't really care as long as there's no legal liability. You're data gets compromised because you didn't notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that's your mistake and no one can sue microsoft for it. As long their negligence doesn't meet the legal definition of negligence, they're not going to put an any kind of effort.
Anti-phishing training could be so much better... "don't put your credentials into anything other that *.microsoft.com". But since these companies won't make any effort, anti-phishing training amounts to "Just be careful or whatever LOL!"