A method of generating a computer user activity log for a user belonging
to a specially monitored group includes allowing a user to logon to a
local computer. The local computer verifying the user account credentials
and creating a user logon session. A token is created by the local
computer for identification of any group membership with which the user
associated and also having the user access privileges. The group
information in the token is compared with a specially monitored group
list. The specially monitored group list may be obtained from a domain
server or may be configured locally. If the user has membership in the
specially monitored group, then a special logon session is created and
activities of the user are recorded.