Is there a GP to enable Data Execution Prevention (DEP) on XP and Vista computers? If not, how do others enable this on their networks (without manually going to each computer)?
Data Execution Prevention configuration is controlled through switches in the boot.ini file. You can use a startup script using bootcfg to modify the boot.ini file. Here's a KB which describes how you can use this tool to modify the file: