Hi Holly,
You can use Restricted Groups to do this. The user will be a member of the local Administrators group on all of your VMs, however as long as access is via the Horizon client only (i.e. you disable RDP through Group Policy), they can't login to other machines anyway.
Lucas