Account recovery with Recovery Admin Enabled - Yubikey

We have the recovery admin enabled for our organization.

" Account recovery administration - On - Based on the encryption method, recover accounts when master passwords or trusted devices are forgotten or lost."

We have a user who is trying to get back into their account after wiping their security key and can no longer log back in. From how the account recovery is worded, an admin for the org should be able to recover/reset their account. His “trusted device” Eg-Yubikey is effectively lost.

Am I wrong in this? And if it is possible, how do I do it? The “recover account” option only changes their password, which does no good in this situation.