Hi,
Have you configured policy-based(crypto map) on routing-based(VTI) VPN?
1. For crypto-map, ensure that in the crypto ACL (the one referenced in your crypto map) you have several entries to match on the traffic from your internal network to Azure, for VTI ensure all traffic to be secured is routed over the VTI.
2. Ensure this traffic is exempted from NAT
3. Ensure that if you applied a VPN filter at the group-policy level, it allows traffic
4. Do you have any ACL's applied globally or at the interface level? What is the output of "show run all sysops"?
Policy-based Guide and Route-Based Guide
Regards,
Cristian Matei.