Let me take a "stab" at it, as the saying goes. So, Im fairly experienced with tunnels to Azure, I had helped lots of customers with it, plus had done extensive testing in the lab as well.
So, I have some question for ya.
1) is this numbered or unnumbered VTI?
2) Regardless what answer is to question1 (though it is somewhat important), can you please share how the route is configured for the subnet on Azure side? (please blur out any sensitive info)
3) As far as topology in smart console, this is SUPER IMPORTANT and it has to be correct...make sure anti-spoofing is disabled and actual remote peer matched EXACTLY how its configured in smart console interoperable object.
4) Is remote peer external IP added to be exmpred for anti spoof checks on external interface? Because if not, it should be
5) Do you have a route to external IP of the peer with default gateway of your upstream router IP?
Thats all I can think of for now.
Best,
Andy