Just to make sure we're on the same page - you've opened the Logon program, chosen the local account, inserted the HMAC-SHA1 (no user input)-configured YubiKey, clicked 'Configure' then either answered yes to the popup or checked 'Enabled' and then logged off or restarted,
removed the YubiKey, and were still able to log in to the local user account you selected?
If so, do you see the 2 copies of the local account? In Windows 10 the credential provider setup results
in 2 versions of the local account showing up - one with a 'key' icon and the other with the icon you set. Both of these versions of the account will require YubiKey to be plugged in although only the 'key' icon one properly surfaces YubiKey-related messages.
We'll get this figured out eventually.