Using classic Outlook for Windows in business environments
If they are automatically flagging these as phishing these emails should never be reaching our junk inbox; there should be a separate box for content that was flagged as malicious and users should be able to confirm the email is legitmate (separate to junk, which would be for content from unknown senders that wasn't flagged as malicious (this doesn't mean it's not malicious, just not flagged as)).
The point of reporting phishing emails is to make the email provider aware, so that they can block future content arriving in people's mail boxes and protect them from malicious content. The response above is utter nonsense. They're putting the cart before horse, and expecting the driver to pull it instead...
Even with automatic flagging, users still need to be able to flag content that goes through the cracks. Now we have the impression that the report feature doesn't work, and lots of emails is also slipping through when it shouldn't be (I get many of the same phishing emails, so the algorithm is not learning, or if it is, it's learning very slowly).