This is now in-place and working. The only stumbling block I ran into was that the employee in question had to already be logged in using a different MFA method in order to "create a new method" and select the FIDO key option. Given no other options, we enabled the phone call choice and entered their direct dial # on the client's phone system. Once they logged in and authenticated this way, we could go to the employee's account in 365, select security, select add-another-method and then choose 'security key'. No software was required, but the inserted key had to be touched as part of the login. It wasn't a fingerprint key, just the most-inexpensive model, which must have used NFC.
The next time someone asks for this, it will be easy. This time, not so much.