AD authentication is recorded in the event log of the domain controller that authenticated the user. You'd have to query each DC in the AD domain to get that information.
Which activities they undertook would also be recorded in the event log. But unless you're auditing activities you would find much detail.
Note that auditing greatly increases the number of events recorded in the security logs. In a large AD you can rapidly run out of space in the log. Something to keep in mind when you're formulating you audit policies.
While PowerShell can help, you'd probably find that a commercial software (or freeware/shareware) product can help you manage and report all the activity.