Sylvain,
You are exactly right: the secAuthority=Default DN is added to the member attribute of ALL groups created by Access Manager in order to meet the schema requirement that the groupOfNames objectclass always have a member attribute defined.
If you look at other products that work with groupOfNames objectclass you will find that they do similar things (cn=dummy or similar).
The reason that secAuthority=Default was chosen as the default group member is that this object is (almost always) defined in an Access Manger system so therefore cannot be created as a user and therefore cannot be misused to get access to groups.
I'm 99% sure this group member has no functional use (other than described).
If you really wanted to you COULD manually remove the secAuthority=Default DN from member attribute once a real user has been added - but then you'd find that you wouldn't be able to remove the last member from the group later on. Best to leave it there.
It was a good question. I hope this confirms things for you :)
Cheers... Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------