If you want, you can actually create Linux VMs in Azure, which give you a little more flexibility with a smaller-profile virtual machine. You can use Wireshark (without downloading and isntalling Winpcap). But you can also shrink the footprint further by using a command-line utility, tcpdump, which is lighter-weight, and outputs in a couple different formats.
The benefit to doing it this way is that your monitoring can be on a very small, lightweight virtual machine that isn't on the same upgrade schedule as all your Windows VMs, and (while Linux has its own security concerns, of course) isn't prey to the same threats.