As we'll be deploying 2FA requirements to certain user groups, we should define messages like userrights-restricted-group-(group) and userrights-restricted-group-(group)-private-conditions for these groups, so that bureaucrats and stewards will know why they cannot assign these groups to certain users.
Groups, for which the overrides should be defined:
- centralnoticeadmin
- checkuser
- interface-admin
- suppress
- wikidata-staff
- wikifunctions-staff
- wmf-officeit
- wmf-supportsafety