Perhaps a better approach to "training the users" might be for the University to actively attempt to phish its own users on a regular basis.
Those who fall for the phishing could be contacted directly, or have email access limited for some period of time (for example, a reduced sending rate limit).
Making self-phishing a regular occurrence (say, weekly) would train users to recognise and ignore it.