Currently 2FA is required for the following groups:
- ombudsman [1]
- sysadmin [1]
- staff [1]
- founder [1]
- global-interface-editor [1]
- global-sysop [2]
- interface-admin [3]
- steward [4]
- centralnoticeadmin [5]
- wmf-supportsafety [6]
On the other hand there are at least the following groups that currently do not require 2FA:
- bureaucrat (can grant anyone including themselves interface-admin, on meta also centralnoticeadmin)
- checkuser (can perform checks which expose potentially user identifying information)
- oversighter (can view oversighted revisions which can contain user identifying information)
- import (can use XML import thus make whatever mess of the wiki like importing edits made in the future and what not)
I do not pretend to have the suggestion list complete. A review of all existing groups should be made, this should include some custom groups, and possibly some of them should have 2FA requirement added.
[1] https://meta.wikimedia.org/wiki/Special_global_permissions
[2] https://meta.wikimedia.org/wiki/Global_sysops
[3] https://meta.wikimedia.org/wiki/Interface_administrators
[4] https://meta.wikimedia.org/wiki/Stewards
[5] https://meta.wikimedia.org/wiki/Meta:Central_notice_administrators
[6] https://meta.wikimedia.org/wiki/Meta:WMF_Support_and_Safety