I know! ;-)
Since this is a productive system I can't easily mess with network settings.
I have changed pfSense LAN address to 192.168.0.1 and the IP of a test server to 192.168.0.22.
The subnet in Azure now is 10.10.0.0. The connection can be established, but machines in the different subnets still do not see each other.
WAN, LAN, and IPsec firewall rules have all been set to allow full IP4 traffic.
Can ping local machine from pfSense LAN and vice versa. Azure VPN shows some traffic in both directions (just a few bytes).