We have a scripted process that takes an Windows 2012 R2 image -> Deploy the server from this image -> run sysprep on the server -> shutdown the server -> Take an image(second image) of the server.
For some strange reason, the machines deployed from the second image all have black color...
Would it be possible to put any type of log / audit in place to see who is using the Active Directory? I'd just like to run it for a week before we shut down the Active Directory.
Please explain how to setup the audit?