For root, group enforcement needs to come after PrivateDevices=y set up according to 096424d1. Add a test to verify this is the case.