Easiest process will be -Contact the Former Employer's IT Department.
This is genuinely the fastest path. Since your father retired, the IT department can:
Remove the device from Intune/Azure AD enrollment
Deregister it from Autopilot
Your father just needs to contact his old IT helpdesk, explain he has a retired personal device, and ask them to remove it from device management. Once they do, a normal reset will work fine. Many companies do this routinely for retiring employees.
2nd option will be Create the Recovery Drive using Microsoft's own Surface Recovery Image, not a generic Windows ISO. Download the exact model's recovery image. Follow all the instructions sited there.