As an outcome of Q3 Tech enforcement work, we want to prevent users who are required to have 2FA enabled, such as interface admins, from being able to disable their last 2FA method.
Acceptance criteria
- Special:AccountSecurity recognizes user groups which require 2FA.
- If 2FA-required user has more than one 2FA method, they are allowed to remove any of them.
- If 2FA-required user has exactly one 2FA method, they cannot remove it.
- If 2FA-required user is prevented from disabling their last 2FA method, they are presented with a message instructing them where they could go and ask for having the relevant user groups removed.
