2FA best practices?

But what attack are you actually protecting against vs. locking your bitwarden account with the yubikey?
Either way you need the yubikey to access the codes.