Here’s a neat article about how to monitor event logs on a domain controller that cause a script to run whenever a new user account is created. The main limitation I see is it will only work on the DC that the account was created on. We really need a generic one that will work on any DC. Other than that, it’s a great idea that I will do some testing on soon.