How to monitor privileged user access?

Date: Sun, 11 May 2008

Hi all. Please excuse me if this issue has been covered before, I searched
but couldn't find any substantial answer.

I have 10-15 privileged users accessing my network from outside (through FW,
via VPN). They access the network and perform various tasks such as
maintaining my Exchange servers and so on. 2 weeks ago I had issues with
some AD objects that have been deleted from the AD. The user responsible for
AD management claimed he did not do it, and this has brought up my question:
How would you suggest that I monitor these users' actions? I have around 100
servers and I would like to know what they did.