Among other things, they can be used as FIDO2 security keys including secure physical confirmation and optionally requiring that the user profile is unlocked.
The hardware attestation support is also drastically nicer and more usable. It doesn't break on upgrades for one thing.