You can create a group policy targeting your domain controllers to enable Security Audit, specifically "Audit account management", you can find the documentation about these events here: https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-account-management
So, you need to configure auditing under Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy.