^^^^^
But if you don't want to swap, change ALL info on it, not just pass, alt, and email, ALL info you can, remove xbox 360 consoles/Xbox one Consoles (if you want links let me know), if he ever used it to send a warranty request, change the info on that too, ( if you want the link let me know), write down all info, both old and new that means, old emails, old passes, old alts, any old ips (find them in the activity section) if it was on his xbox one his consoles serial number, if you use a prepaid card on the account save it.
Purge all emails and folders as well (make sure to go through them and write down any old aliases/alts that might have been used for the account), also when securing, make sure to remove all trusted devices so if he still has access on his PC he can't change any info
change recovery codes, app passes etc etc enable 2 step