If you can phish the pw you can phish the totp. People type it in right after they type in the pw.
If you really must protect the user from themself (which I don't think you should, except in much more extreme circumstances), you can generate the password for them.