The two most common reasons for this message are:
the gateway addresses are not matching on both sides
confirm that the ip address the SSG has for Azure and Azure for the SSG are correct
The policy crypto packages are not matching between Azure and the ssg
confirm that these selections match what the Azure side has configured
set ike p1-proposal "AZURE-P1_Proposal" preshare group2 esp aes256 sha2-256 hour 8
set ike p2-proposal "AZURE-P2_Proposal" group2 esp aes256 sha2-256 hour 3