What are common “effects” in Azure Policy?

Why is this policy used?

Can User Administrator manage device identities?

Who typically uses this role?

What can a User Administrator NOT do?