Spent way too much time figuring out why RDP with a FIDO2 key didn't work. Turns out unlike the WHFB path, using web sign-in for RDP uses a TPM bound (temp, I think) key for TLS. TPM 2.0 up to certain spec versions don't properly implement the required algos for TLS 1.3 signing, breaking it all... And of course the RDP client gives you only a vague error message that maybe your password is expired 🙄