Just having the security key isn't enough to log in.
You still have to auth the key when using it, with fingerprint or face recognition, or PIN.
Since Yubikeys (most common versions) only has a simple touch area, that isn't going to be enough, you will have to create and use a PIN. That is also the default when using a Yubikey for FIDO2 stuff (not Google, which is/was U2F only).
As a 2FA device, the Yubikey (other brands may work differently) only require touch for Google accounts, but for O365 I also have to provide a PIN (touch and PIN!).
For the really security conscious, Yubico also offer Yubikeys with BIO check.
So far I'm quite happy with my regular 5-series. I have a whole bunch. I even gave one to each of my colleagues on the IT department as X-mas gifts. Got to push the envelope somehow. 🙂
--
https://wheretofind.me/@NoSubstitute