JaCarta Management System by Aladdin-RD manages the lifecycle of authentication and electronic signature hardware and software, including common tokens and smart cards from various vendors, cloud tokens, stored objects, smart card readers, and hardware/software OTP/U2F authenticators. It includes a powerful two-factor authentication server (2FA) JaCarta Authentication Server (JAS) for providing a second authentication factor to companies that are not ready to deploy a PKI infrastructure or wish to ensure enhanced authentication using one-time passwords for some of their employees. JaCarta Management System is certified by the FSTEC of Russia and registered in the registry of Russian software for computers and databases (No. 311). It automates the process of individual accounting of cryptographic protection means, manages the lifecycle of tokens and software authentication means, fully automates the application of information security policies, provides a self-service service, ensures high performance, scalability, and fault tolerance, and tracks actions of users and administrators. It supports all tokens and smart cards from the JaCarta line, popular models from third-party manufacturers (Rutoken, ESMART), as well as hardware and software OTP and U2F authenticators, including cloud tokens (CryptoPro DSS). The platform automatically enforces security policies through a profile mechanism that connects entities such as 'user,' 'token,' 'software or hardware OTP/U2F authenticator,' or 'object on the token.' A profile is a set of rules (policies) applied to these entities. A profile can be applied to a container (OU) of a resource system, a group, or an individual user. For example, the profile can specify parameters for certificates issued to user tokens from a specific OU. With the appropriate configuration, adding a new user to the specified OU will trigger the automatic issuance of the specified certificate and its recording on the token during synchronization (policy application). Removing a user from the OU will automatically revoke their certificate and delete it from the user's token. A flexible policy application filtering mechanism has been implemented, including the use of Microsoft Active Directory security groups. Users have a convenient self-service portal through JMS, allowing them to perform all necessary permitted lifecycle operations for hardware tokens/smart cards and the objects stored on them, according to the policies set by administrators. Self-service capabilities apply equally to hardware OTP-U2F and software PUSH/OTP/SMS authenticators.