Meraki has a vMX that runs in Azure, so you would use that.
https://meraki.cisco.com/products/appliances/vmx100
There would be no point in using a seperate security product like zscaler at the branch level. The MX already has all the security you need.
https://meraki.cisco.com/products/appliances
I think SSL inspection is almost pointless these days. It is better to simply inspect where the connections are connecting to. This is the approach Meraki uses. Dynamically content filtering.
https://meraki.cisco.com/technologies/content-filtering
Meraki have actually played with SSL inspection, but it is highly possible it will never get released. The small amount of extra things you can catch over simple connection monitoring, considering the massive amount of CPU it burns, and the pain of having to install root certificates onto ever device behind the SSL inspection device, makes it not worth while.
I have seen very few sites deploy SSL inspection, and everyone one of those eventually turned it off. Managing the certificates becomes just too hard,