Running into the same ... and it's infuriating.
At first thought might've had something to do with not having GUI session, but even with that and actively logged in to RDP, getting different results.
Theorizing similar : something happening with GUI that's initiating some security aspect to "allow" keychains differently.
Hoping someone from Apple can speak to this.