I apologize for my ignorance in advance: having a private key file password-protected does nothing?
I guess I'm not understanding what you mean by "compromised"?
I'm not saying the password protection does nothing, it makes the key harder to crack but it's not another factor. It's simply an extension of the existing key. In other words, it's just a longer password.
If somebody steals your password protected private key file, having the password protection there means they have to bruteforce the password. It does not 'do nothing'. Its an extra layer. If your password is secure enough, it can protect you from having the ssh private key decrypted.
You're entirely right -- the "proper" way is to login with MFA, enable SSH, do your thing, and then re-disable SSH.