It is possible to restrict FIDO2 keys enrollment by their AAGUIDs. Not something the general public will encounter, but a business using FIDO2 keys as their MFA can limit which hardware can be used, for example limit the enrollment to specific AAGUIDs from Yubico
https://support.yubico.com/hc/en-us/articles/360016648959-YubiKey-Hardware-FIDO2-AAGUIDs
That's something I had to look into when configuring our Azure environment.