Using PowerShell to filter events on the domain controller to find the admin account used to disable the user.