In addition to keeping track of when changes to certificate services take place such as denied certificate request etc., how do you keep track of when Active Directory objects are created or removed within a Windows Server 2003 Active Directory Infastructure?