I have a need to pass through a YubiKey to a Windows (10) VM guest
such that Windows in the guest will let me use it with physical touch
activation for 2FA.

For those times, I am physically at the VM host, so I don't need
_remote_ redirection into the guest, and I'm fine with plugging and
unplugging the YubiKey physically on an as-needed basis.

If I simply redirect the USB device through the virt-manager GUI, my
experience is that it has at best worked very much unreliably, and
often not at all.

Searching the web hasn't helped.

Does anyone have a recipe for that to work _reliably_?

