maybe you already got this working but for the benefit of anyone else reading, VPN with Azure is feasible. The local auth method I think is always logged as "reserved" and it refers to the method configured on the NGFW, your log tells that Azure is using PSK.
If there are no other messages related to the negotiation failure, enable IPsec diagnostics for the firewall (rightclick fw, options, diagnostics) and then try initiating the tunnel again or wait for other end to initiate it. The other IPsec log messages surrounding the "initiator/responder failed" error would then tell you in more detail why it failed. If there is some kind of error code logged you can find the explanations here (not changed since v5.0): http://help.stonesoft.com/onlinehelp/StoneGate/SMC/5.3.7/SGAG/SG_FWIPS_LogFieldV alues/VPN_Error_Codes.htm