ad user logout logging

auditpol.exe /set /subcategory:”Sensitive Privilege Use” /failure:enable /success:enable

Get-EventLog -LogName Security | ?{$_.message -like “*locked*tk*”} | fl -property *

auditpol.exe /get /category:*