If you want to be logged in with your user certificate and PIN from your Yubikey insted of the ad-user password… thats what is already possible. Set “Edit first factor” in the Global user Settings or specific organisational unit / user setting for Windows application to “Smartcard”.
PS: If you want to let the users use the web app, you can set the FIDO2 for web application.