That’s a pretty big foul. I use a different hardware key plugged into each workstation I use and then some “roaming” keys that I can use for backup, travel, etc.
To work around this I sync multiple Ledger devices with identical seed phrases which allow for duplicate FIDO devices that can be shared with any teams that need break-glass root account access.
AWS employees are issued two Yubikeys, which are registered for all internal auth use cases. For me, but not for thee, it seems.
And probably never will because the official unofficial solution is to use SSO and have your identity provider handle that.