Hi,
1: Please make sure your private IPs/subnets for both the VPN (Azure side) are different.
2: It's not mandatory to have new interface with public IP on the SSG. You can use any IP/Interface which has reachablity to the Azure cloud.
3: Configure your static route pointing to the tunnel interface. Once again, as I mentioned try not to have overlapping subnets in the policy and route based VPNs.
4: KB https://kb.juniper.net/InfoCenter/index?page=content&id=KB14330&actp=METADATA for route based VPN on SSG.
Thanks,
Vikas