but I donʼt know how if thatʼs right or how to get condor_drain to use it.
I would hope that if condor_token_list running as the same user running condor_drain lists a token, then condor_drain (et omnes alii) would find and use it, but: you can try
_CONDOR_SEC_TOKEN_DIRECTORY=/etc/condor/tokens.d condor_drainto see if setting the "user" token directory to the "system" token directory bypasses whatever the problem is.
-- ToddM