thanks for the response! it looks like there are some PAM-based ways of implementing this functionality in Qubes OS:
- https://github.com/adubois/qubes-app-linux-yubikey
- https://old.mig5.net/content/yubikey-2fa-qubes-redux-adding-backup-key.html
I’ll explore this strategy, thanks for the guidance.