Best solution to monitor a terminated employees email account?

Best solution to monitor a terminated employees email account?

Hi,
I am looking for the best solution to monitor a terminated employees account for awhile as suspected fraud is going on.  I changed the password immediately but can they just reset it somehow?  I chose the option Sign-out from all devices but did not choose the option for them to change the password at next login.  Does this keep them out?

Do I delete their account and use their email as an alias in the admin account so that we can receive their emails?

Any suggestions would be appreciated.  This is time sensitive.